2026 Ultrahuman — internal analytics tool breach; ~0.1% of users (~700+)
Data compromised
Wellness and fitness-related analytics fields for a small user subset; contact details per notices
Technical writeup
Ultrahuman confirmed in early June 2026 that attackers used credentials stolen from a malware-infected employee laptop to access an internal analytics system on March 27, 2026. TechCrunch and Cybernews reported the company notified affected customers by email, detected the intrusion within hours, and took the system offline; Ultrahuman said no passwords, payment data, or ring devices were compromised but acknowledged wellness-related data was accessed for roughly 0.1% of users—about 700 individuals based on ~700,000 monthly active users cited in press. A later website notice indicated a small subset had fitness-related fields exposed. BreachHistory uses the conservative 700 floor until the company publishes an exact count.
Root cause
Stolen employee credentials via malware-infected laptop; unauthorized read-only analytics access