← Blog

Hims & Hers: Third-Party Tickets and Social Engineering

Share on X

In February 2026, Hims & Hers reported suspicious activity tied to a third-party customer service system used for support tickets. The company described unauthorized access to ticket data between approximately 4–7 February 2026 (with awareness on 5 February in public summaries). Data classes cited in regulatory-style and press summaries included names, emails, phone numbers, and addresses, with some materials referencing treatment-category or other ticket context for customers who had contacted support over a longer lookback period.

What was not reported affected

Disclosures emphasized that the company’s core clinical systems and communications between patients and licensed providers were not described as compromised in the same way as the vendor ticketing environment.

Root cause framing

Secondary reporting and investigations cited social engineering directed at vendor-side personnel (including references to two employees in some accounts)—underscoring risk in outsourced support stacks that sit adjacent to, but outside, hardened clinical record systems.

Canonical record: Hims & Hers 2026 on BreachHistory.

Sources: ClassAction.org, Claim Depot