2026 Hims & Hers — third-party customer service platform (social engineering; Feb 4–7)
Data compromised
Names, emails, phones, addresses; treatment-related or ticket context per disclosed categories (not core EHR)
Technical writeup
Hims & Hers Inc., a U.S. telehealth company, disclosed unauthorized access to a third-party customer service platform used for support tickets. The company reported becoming aware of suspicious activity on February 5, 2026, and determined that ticket data may have been accessed or acquired without authorization between approximately February 4 and February 7, 2026. Public summaries described exposure of names, email addresses, phone numbers, and postal addresses from service tickets; some notices referenced treatment-category or other customer-service ticket content for users who had contacted support over a longer historical window. Hims & Hers stated core clinical records and communications between patients and licensed providers were not involved. Secondary reporting and class-action summaries cited social engineering targeting vendor-side personnel (e.g., two employees in some accounts). Direct notifications to consumers were summarized in press into April 2026.
Root cause
Social engineering against third-party customer service vendor; unauthorized access to support tickets
References
- https://www.darkreading.com/cyberattacks-data-breaches/hims-breach-exposes-sensitive-phi
- https://www.malwarebytes.com/blog/data-breaches/2026/04/support-platform-breach-exposes-hims-hers-customer-data
- https://www.classaction.org/data-breach-lawsuits/hims-and-hers-april-2026
- https://www.claimdepot.com/data-breach/hims-hers-2026