BreachesHIGH

Hims & Hers - Customer Data Breach Exposed

Featured image for Hims & Hers - Customer Data Breach Exposed
#Hims & Hers#ShinyHunters#Zendesk#Okta#data breach

Original Reporting

MWMalwarebytes Labs

AI Intelligence Briefing

CyberPings AI·Reviewed by Rohit Rana
Severity LevelHIGH

Significant risk — action recommended within 24-48 hours

⚔️
⚔️ BREACH SUMMARY
Victim Organization
Industry Sector
Attack Type
Data Exposed
Records Affected
Threat Actor
Entry Point
Dwell Time
Discovery Method
Ransom Demanded
Regulatory Impact
🎯

Basically, hackers stole personal data from Hims & Hers customers through a security breach.

Quick Summary

Hims & Hers has reported a data breach affecting customer support data. Sensitive information was accessed by hackers, raising privacy concerns. Customers are advised to stay vigilant against potential scams.

What Happened

Hims & Hers, a prominent telehealth company, recently discovered a significant breach involving its customer service platform. On February 5, suspicious activity was detected on their third-party customer service system. An investigation revealed that between February 4 and February 7, unauthorized access to customer service tickets occurred, leading to the potential exposure of sensitive customer data. The breach was confirmed on March 3, when the company acknowledged that personal information was compromised.

Who's Affected

The breach impacts customers of Hims & Hers, a company that provides subscription-based treatments for various health issues, including hair loss and mental health. With annual revenues nearing $1 billion, the exposure of customer support data is particularly concerning. While medical records and direct doctor communications were not compromised, the stolen data may still include names, contact information, and other details that customers would prefer to keep private.

What Data Was Exposed

The compromised data primarily consists of customer support tickets. Although Hims & Hers has assured that no medical records were involved, the nature of the information exposed raises serious privacy concerns. Even basic contact details can reveal sensitive connections to health-related issues, making this breach particularly alarming for affected individuals.

The Attackers

Reports indicate that the ShinyHunters extortion gang was behind the breach. This group is known for compromising single sign-on (SSO) accounts through social engineering tactics. By impersonating IT support and tricking employees into providing credentials, they can gain access to various connected services, including customer support platforms like Zendesk. This method has previously led to significant breaches at other companies, highlighting a troubling trend in cyberattacks targeting customer service systems.

Why (and How) to Stay Vigilant

In response to the breach, Hims & Hers is offering 12 months of free credit monitoring to affected customers. However, this measure alone may not be sufficient to prevent phishing attacks that exploit the stolen information. Cybercriminals may use the compromised data to craft convincing scams or extortion attempts, potentially targeting victims with personalized communications referencing their health-related purchases.

To protect yourself:

  • Take advantage of the free credit monitoring offered by Hims & Hers.
  • Be cautious of unsolicited emails or texts that mention your treatments or support history.
  • Avoid clicking on suspicious links and do not share personal information with unknown contacts.
  • Verify any communications directly with the company through trusted channels.
  • Consider using tools that monitor the dark web for your personal information, such as Malwarebytes’ Digital Footprint scanner.

Staying informed and vigilant is crucial in the wake of such breaches, as the risks extend beyond immediate financial concerns to long-term privacy implications.

🔍 How to Check If You're Affected

  1. 1.Check for any suspicious emails or communications referencing your support tickets.
  2. 2.Monitor your financial accounts for unauthorized transactions.
  3. 3.Use a dark web monitoring tool to see if your personal information is being traded.

🏢 Impacted Sectors

Healthcare

Pro Insight

🔒 Pro insight: The ShinyHunters' tactics highlight the vulnerability of third-party support platforms, necessitating robust security measures across all service providers.

Sources

Original Report

MWMalwarebytes Labs
Read Original

Related Pings

HIGHBreaches

European Tourist Sites - Thousands Affected by Breach

A major cyberattack on Vivaticket disrupted online ticketing for thousands of European tourist sites. Sensitive customer data was exposed, affecting many visitors. Authorities are assessing the damage and working on recovery.

SC Media·
HIGHBreaches

Breach Monitoring - Why Simple Solutions Fail Against Infostealers

Infostealers are increasingly bypassing traditional defenses, making basic breach monitoring inadequate. Organizations face significant risks from credential theft, costing millions. A strategic shift is essential for effective protection.

BleepingComputer·
HIGHBreaches

Syria’s Security Failures Exposed by Government Account Hack

A recent hack exposed Syrian government accounts, revealing significant cybersecurity weaknesses. This incident raises concerns about the state’s digital security practices and its ability to communicate effectively. Experts warn that without urgent reforms, Syria's digital infrastructure remains at risk.

Wired Security·
LOWBreaches

T-Mobile - Clarifies Details on Recent Data Breach Incident

T-Mobile has clarified that a recent data breach involved an insider threat affecting only one account, with no financial data compromised. Customers are advised to monitor their accounts.

SecurityWeek·
HIGHBreaches

CBP Facility Codes Exposed in Quizlet Flashcards Leak

A significant breach has occurred as sensitive security codes for Customs and Border Protection facilities were leaked through public Quizlet flashcards. The incident raises serious concerns about national security protocols.

Wired Security·
HIGHBreaches

Iran Handala Group Breaches Israeli Defence Contractor PSK Wind

Iranian hackers have breached PSK Wind Technologies, an Israeli defense contractor. Sensitive military data has been stolen, posing serious risks to national security. Organizations must strengthen their defenses against such cyber threats.

Security Affairs·