250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Description
In July 2026, two healthcare organizations, Clover Health Investments and AngMar Management Services, suffered data breaches resulting in the theft of personally identifiable information (PII) and protected health information (PHI) of over 250,000 individuals. Clover Health's breach involved social engineering attacks compromising employee accounts, exposing names, birth dates, insurance identifiers, and account numbers. AngMar Management Services experienced a ransomware-related breach with over 700 GB of data stolen, including sensitive patient details such as Social Security numbers, medical history, and prescription information. Both companies reported the incidents to the US Department of Health and Human Services and were added to its breach portal.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Two separate data breaches impacted over 250,000 individuals associated with Clover Health Investments and AngMar Management Services in 2026. Clover Health's breach was caused by social engineering targeting non-managerial employee accounts, leading to the theft of PII and PHI including names, dates of birth, insurance identifiers, and account numbers. AngMar Management Services detected suspicious activity linked to the Interlock ransomware group, which published stolen data on a leak site. The stolen data included extensive patient information such as Social Security numbers, diagnosis details, medical history, and prescription data. Both organizations notified the US Department of Health and Human Services and were listed on its data breach portal.
Potential Impact
The breaches exposed sensitive personal and health information of approximately 264,873 individuals, including PII and PHI such as names, birth dates, Social Security numbers, insurance identifiers, medical histories, and prescription details. This exposure increases the risk of identity theft, fraud, and privacy violations for affected individuals. The involvement of a ransomware group in the AngMar breach suggests potential extortion and further operational disruption risks for the organization.
Defensive Guidance
No specific remediation or patch is applicable as these incidents are breaches resulting from social engineering and ransomware attacks. Organizations should follow incident response protocols, notify affected individuals, and comply with regulatory reporting requirements as done by the affected companies. Enhanced employee training on social engineering, robust access controls, and ransomware defenses are recommended to reduce future risk.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/250000-impacted-by-data-breaches-at-new-jersey-texas-healthcare-firms/","fetched":true,"fetchedAt":"2026-10-05T12:48:20.782Z","wordCount":938}
Threat ID: 6ac39c952cdf04f656fe0988
Added to database: 10/05/2026, 12:48:21 UTC
Last enriched: 10/05/2026, 12:48:26 UTC
Last updated: 10/05/2026, 18:48:21 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.