Cyber Incident Victim: Hims & Hers
Date:
Feb 2026
Location:
United States of America
Summary
Hims & Hers disclosed that hackers gained access to its third‑party ticketing system through a social engineering attack and exfiltrated customer names, contact information and other unspecified personal data from support tickets, while stating that medical records were not compromised. The company said the breach did not affect medical records but noted that support tickets may contain sensitive personal and healthcare‑related information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The technology news outlet TechCrunch reported on April 2 2026 that Hims & Hers, a telehealth company that sells weight‑loss drugs and sexual‑health prescriptions, filed a data breach notice with the California attorney general’s office on the preceding Thursday. In that notice the company disclosed that hackers had compromised its third‑party ticketing system between February 4 and February 7 2026 and had stolen reams of support tickets submitted by customers. The stolen tickets contained personal information that users had sent to the company’s customer‑support team. The breach notice specifically noted that the attackers had taken customer names and contact information as well as other unspecified personal data that Hims & Hers had redacted in the public filing.

Although the company asserted that customer medical records were not affected by the incident, the breach notice warned that the nature of customer‑support systems means that the compromised data may contain sensitive information about a person’s account, personal details and healthcare. The notice also stated that the exact number of individuals whose information was compromised had not yet been determined, noting that California law requires disclosure only when a breach affects 500 or more state residents. The company declined to disclose the specific categories of data that were taken when asked for clarification by TechCrunch.
Jake Martin, a spokesperson for Hims & Hers, told TechCrunch that the breach resulted from a social‑engineering attack in which hackers tricked employees into granting them access to the ticketing system. Martin said that the stolen data “primarily included customer names and email addresses,” but the company did not elaborate on any other data types that might have been taken. When questioned about possible extortion attempts, the company said it would not comment on whether it had received any communication from the attackers, such as a ransom demand.
The TechCrunch article placed the Hims & Hers incident in the context of a broader trend, noting that in recent months customer‑support and ticketing systems have become attractive targets for financially motivated hackers who seek to exfiltrate customer data and extort payments. It referenced a 2025 incident in which Discord suffered a breach of its customer‑support ticketing system that exposed the government‑issued identification of roughly 70,000 users who had submitted driver’s licenses or passports for age verification. The article concluded by observing that further forensic details, legal actions and regulatory responses were still remained pending at the time of publication.
