CSIDB logo
Incident

Ultrahuman

Incident posture

Attack window
Mar 2026
Location
India
Status
Resolved
CIA posture
Available to members
Updated
2026-09-10 11:06

Linked entities

Victim
Ultrahuman
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Jun 2026
Resolved
Mar 2026

Summary

Ultrahuman, a wearable tech startup, reported that hackers accessed customer wellness data after stealing an employee’s credentials via malware. The breach occurred in an internal analytics system, giving attackers read‑only access to health metrics such as sleep, activity and recovery for about 0.1% of its roughly 700,000 active users, or roughly 700 individuals. The company detected the intrusion quickly, took the affected system offline, revoked access and began notifying affected users after completing its investigation. It said passwords, payment data and device hardware were not compromised, and it is working with regulators while still determining whether any data was exfiltrated.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 27, 2026, attackers infiltrated an employee's computer at Ultrahuman using malware and stole login credentials. The stolen credentials were used to gain unauthorized access to an internal analytics system belonging to the wearable health‑tech startup. Ultrahuman’s security alerting systems detected the intrusion within hours of the breach. Upon detection, the company took the affected system offline and revoked all access associated with the compromised credentials. The vulnerability that allowed the intrusion was immediately patched after the system was isolated.

Ultrahuman reported that approximately 0.1% of its users had wellness data accessed in the incident. With roughly 700,000 monthly active users on the platform, this corresponds to at least 700 individuals whose health metrics were exposed. The accessed data included sleep, activity, and recovery metrics tracked by the Ring Air and Ring Pro devices. The company stated that passwords, payment information, production systems, and the Ultrahuman Ring hardware itself were not compromised. Ultrahuman declined to disclose the exact number of affected users and noted that its FAQ described the threat actor’s access as read‑only, while refusing to confirm whether any data was exfiltrated.

Affected users were notified by email after the company completed an audit to determine the full scope of the breach and the specific data involved. Ultrahuman also informed relevant regulators of the incident as part of its response process. CEO Mohit Kumar said that security systems detected the intrusion within hours and that the vulnerability was closed swiftly. He explained that the delay in user notification was necessary to fully investigate the scope and ascertain what type of data had been leaked. The startup, founded in 2019 and backed by Nexus Venture Partners, Steadview Capital, and Blume Ventures, has raised around $103 million to date.

Sources

Sources available to members: 2 sources.

CSIDB