Breaches · 157 days ago
Hims & Hers disclosed a breach of its third-party customer support ticketing system from February 4 to 7. Attackers accessed and stole support tickets containing customer names, contact information, and other redacted personal data. The company says medical records were not accessed, but support tickets often include sensitive health-related details embedded in customer communications.
This breach highlights that third-party support platforms can expose contextual personal and health information even without direct access to electronic health records. Such data can enable phishing, impersonation, or account takeover attacks. Organizations should treat support ticket data as highly sensitive and audit third-party integrations accordingly.
4 sources covering this story
Hims Breach Exposes the Most Sensitive Kinds of PHI
Threat actors breached the telehealth brand, and now they may know patients' personal health details.
Hims & Hers says limited data stolen in social engineering attack
The telehealth provider said hackers gained access to a third-party customer service platform, but medical records remained secure.
Hims & Hers warns of data breach after Zendesk support ticket breach
Telehealth giant Hims & Hers Health is warning that it suffered a data breach after support tickets were stolen from a third-party customer service platform.
Telehealth giant Hims & Hers says its customer support system was hacked | TechCrunch
telehealth giant says hackers stole customer support ticket data over the course of several days in February.
Part of the PlainSec briefing for 2026-04-03