Back to News
technology

Telehealth giant Hims & Hers says its customer support system was hacked

Zack Whittaker
Loading...
3 min read
0 likes
⚡ Quantum Brief
A telehealth provider confirmed a February data breach where hackers accessed its third-party customer support system between February 4–7, stealing support tickets containing personal data like names, contact details, and unspecified sensitive information. The breach, disclosed in a California filing, did not expose medical records but likely included account and healthcare-related details from support interactions. The company has not revealed the number of affected users. Hackers used social engineering to trick employees into granting system access, according to a spokesperson. The stolen data primarily included names and email addresses, though other specifics remain undisclosed. No ransom demands have been reported, but customer support systems are increasingly targeted for extortion. A similar 2025 Discord breach exposed 70,000 users’ government-issued IDs via its ticketing system. The company has not detailed mitigation steps or whether affected users were notified. California law mandates disclosure for breaches affecting 500+ residents.
AI Audio Summary
0:00 / 0:00
Click to play
generated-image (59).png
Quantum News · Media Library

The first StrictlyVC of 2026 lands in San Francisco on April 30. Tickets are limited. Register here.Save up to $680 on your Disrupt 2026 pass. Ends 11:59 p.m. PT tonight. REGISTER NOW. Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us Hims & Hers, the telehealth company that sells weight-loss drugs and sexual health prescriptions, has confirmed a data breach affecting its third-party customer service platform.The healthcare company said in a data breach notice filed with the California attorney general’s office on Thursday that the hackers stole data about user requests sent to the company’s customer support team. The company said hackers broke into its third-party ticketing system between February 4 and February 7 and stole reams of support tickets, which contained personal information submitted by customers.The data breach notice said the hackers took customer names and contact information, as well as other unspecified personal data that Hims & Hers left redacted in the letter.Although the company says customer medical records were not affected by the breach, the nature of customer support systems means that the data may contain sensitive information about a person’s account, personal information, and healthcare.It’s not yet known how many individuals had personal information compromised in the hack. Under California law, companies are required to disclose data breaches involving 500 or more state residents.Jake Martin, a spokesperson for Hims & Hers, told TechCrunch in a statement the company was hit by a social engineering attack, in which hackers trick employees into granting access to their systems. The spokesperson said the stolen data “primarily included customer names and email addresses.” The company did not say what specific types of data were taken, when asked by TechCrunch.The company would not say if it has received any communication from the hackers, such as a demand for money.In recent months, customer support and ticketing systems have become rich targets for financially motivated hackers, who have raided databases containing customer information and extorted companies into paying a ransom.Last year, Discord had a data breach that affected its customer support ticketing system and exposed the government-issued IDs of around 70,000 people who had submitted their driver’s licenses and passports to the company to verify their age.Topics Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com. StrictlyVC kicks off the year in SF. Get in the room for unfiltered fireside chats with industry leaders, insider VC insights, and high-value connections that actually move the needle. Tickets are limited. Anthropic took down thousands of GitHub repos trying to yank its leaked source code — a move the company says was an accident Anthropic is having a month Google is now letting users in the US change their Gmail address Why OpenAI really shut down Sora The Pixel 10a doesn’t have a camera bump, and it’s great Anthropic’s Claude popularity with paying consumers is skyrocketing Let’s take a look at the retro tech making a comeback © 2026 TechCrunch Media LLC.

Read Original

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.