Hims & Hers disclosed a breach of its third-party customer support platform after attackers used a social engineering attack to gain access between February 4 and February 7. The company said the intruders accessed and stole customer support tickets, and a breach notice was filed with the California attorney general's office.
The compromised data primarily included customer names and email addresses, but support submissions may also have contained other personal, account, and healthcare-related information provided by users. Hims & Hers said customer medical records were not affected, did not disclose how many individuals were impacted, and has not said whether the attackers made any ransom or extortion demand.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Hims & Hers started mailing breach notification letters to affected individuals after the incident and offered 12 months of complimentary single-bureau credit monitoring and identity theft protection. The company also said it had notified law enforcement and regulators as part of its response.
BleepingComputer reported that the Hims & Hers breach was allegedly carried out by the ShinyHunters extortion gang as part of a broader campaign abusing compromised Okta SSO accounts to access SaaS platforms. In Hims & Hers' case, the attackers reportedly used an Okta SSO account to access the company's Zendesk instance and steal millions of support tickets.
Hims & Hers disclosed the incident in a notice filed with the California attorney general's office. The company said customer medical records were not affected, but did not disclose how many individuals were impacted.
On March 3, 2026, Hims & Hers determined that the compromised support tickets contained personal information for a limited set of individuals, including names and contact details. The company said the exposed data did not include personal healthcare information or patient-provider communications.
Between February 4 and February 7, attackers used a social engineering attack to gain access to Hims & Hers' third-party customer service ticketing platform. They accessed customer support tickets containing personal information, primarily names and email addresses, and potentially other account and healthcare-related details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcedarkreading.com
Open sourceteiss.co.uk
Open sourcehipaajournal.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.