CSIDB logo
Incident

Hims & Hers

Incident posture

Attack window
Feb 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 00:57

Linked entities

Victim
Hims & Hers
Threat actors
0 actors
Sources
4 sources

Timeline

Occurred
Feb 2026
Discovered
Feb 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

Hims & Hers disclosed that attackers gained unauthorized access to its third‑party customer‑support ticketing system through a social engineering scheme, allowing them to view and copy support tickets that contained customers’ names, email addresses and other personal information submitted during inquiries. The company said the breach did not compromise its core medical records, but the ticket data could include health‑related details because of the nature of the support requests. After detecting the suspicious activity, Hims & Hers secured the affected service, investigated the scope of the exposure and began notifying affected individuals, offering them credit‑monitoring services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 5, 2026, Hims & Hers discovered suspicious activity on its computer network involving a third‑party customer service platform. The company later determined that unauthorized access to the platform occurred between February 4 and February 7, 2026. Attackers gained entry through a social engineering scheme that tricked employees into granting system access. The compromised platform was identified as Zendesk, a ticketing system used for customer support.

During the intrusion, attackers accessed certain customer service tickets that contained names, email addresses and other unspecified personal data submitted by customers. Hims & Hers stated that its core medical records were not affected, but the tickets may contain sensitive health‑related information because the support system captures details of customer inquiries. The company determined that the accessed tickets held names and unspecified medical information belonging to a limited set of affected customers. Under California law, the breach triggered a disclosure requirement because it potentially impacted 500 or more state residents, although the exact number of individuals was not disclosed.

Hims & Hers said it promptly took steps to secure the affected service after detection, though the attackers retained access until February 7. Approximately one month after determining what data was taken, the company began notifying the affected customers. As part of its response, Hims & Hers offered those customers a year of free credit monitoring and guidance on identity protection. The firm filed a data breach notice with the California Attorney General’s office on April 2, 2026, and submitted a Form 8‑K to the U.S. Securities and Exchange Commission the same day. Edelson Lechtzin LLP announced an investigation into potential class‑action claims arising from the incident, and the company has not disclosed whether it received any communication from the attackers such as ransom demands.

Sources

Sources available to members: 4 sources.

CSIDB