{"id":244052,"date":"2026-06-03T17:30:52","date_gmt":"2026-06-03T17:30:52","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/06\/03\/ultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool-techcrunch\/"},"modified":"2026-06-03T17:30:52","modified_gmt":"2026-06-03T17:30:52","slug":"ultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/06\/03\/ultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool-techcrunch\/","title":{"rendered":"Ultrahuman says hackers accessed customers&#8217; wellness data via internal tool | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Wearable health-tech startup <a href=\"https:\/\/www.ultrahuman.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ultrahuman<\/a> said hackers gained unauthorized access to customers\u2019 wellness data after stealing an employee\u2019s credentials through malware.<\/p>\n<p class=\"wp-block-paragraph\">On Wednesday, the India-based startup informed affected customers of the incident via email, stating that the breach occurred on March 27 and involved a system used for internal analytics. The company said it detected the intrusion promptly, took the affected system offline, and revoked all access.<\/p>\n<p class=\"wp-block-paragraph\">Founded in 2019, Ultrahuman sells smart rings and metabolic health-tracking devices that enable users to monitor metrics such as sleep, activity and recovery. The startup is best known for its <a href=\"https:\/\/techcrunch.com\/2023\/08\/10\/ultrahuman-ring-air-review\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ring Air<\/a>, which competes with the Oura Ring, and recently <a href=\"https:\/\/techcrunch.com\/2026\/02\/27\/ultrahuman-unveils-new-smart-ring-as-it-awaits-u-s-clearance-after-oura-dispute\/\" target=\"_blank\" rel=\"noreferrer noopener\">introduced the Ring Pro<\/a> with upgraded sensors and battery life.<\/p>\n<p class=\"wp-block-paragraph\">Confirming the incident, Ultrahuman told TechCrunch that the attackers gained access using credentials stolen from an employee\u2019s malware-infected laptop, resulting in wellness data belonging to about 0.1% of users being accessed. <\/p>\n<p class=\"wp-block-paragraph\">Based on the company\u2019s previously reported figure of <a href=\"https:\/\/techcrunch.com\/2026\/03\/24\/ultrahuman-ramps-up-u-s-push-with-ring-pro-as-oura-tightens-grip\/\" target=\"_blank\" rel=\"noreferrer noopener\">roughly 700,000 monthly active users<\/a>, that would equate to at least 700 customers who had their health data accessed. Ultrahuman did not dispute this figure, but declined to disclose the exact number of customers affected. The company said no passwords, payment information, production systems, or Ultrahuman Ring devices were compromised.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOur security alerting systems detected the incident within hours, and we closed the vulnerability swiftly,\u201d Ultrahuman CEO Mohit Kumar said in a statement to TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">Kumar added that the startup was notifying regulators and had delayed informing affected users while it audited the full scope of the incident and determined what data had been affected.<\/p>\n<p class=\"wp-block-paragraph\">Ultrahuman declined to share any details on whether it received any communication from the hackers responsible for the incident, nor say what exactly constitutes \u201cwellness data.\u201d The breach highlights how wellness tracker startups, like Ultrahuman and also Oura, store users\u2019 data on their servers in a way that allows their employees  \u2014 as well as governments and malicious hackers \u2014 to access customers\u2019 health data.<\/p>\n<p class=\"wp-block-paragraph\">The startup said in an FAQ <a href=\"https:\/\/www.ultrahuman.com\/legal\/notice-march-2026\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">published<\/a> on its website that the threat actor obtained \u201cread-only\u201d access to the affected system. However, the company declined to confirm whether its investigation had determined if any customer data was exfiltrated.<\/p>\n<p class=\"wp-block-paragraph\">Ultrahuman counts Nexus Venture Partners, Steadview Capital, and Blume Ventures among its investors. The startup has <a href=\"https:\/\/tracxn.com\/d\/companies\/ultrahuman\/__RSGzV5aJJQdyE6IBruBLiGXE7STOO3AfA1qtqw5Z4zo\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">raised around $103 million<\/a> to date, per Tracxn.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/06\/03\/ultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wearable health-tech startup Ultrahuman said hackers gained unauthorized access to customers\u2019 wellness data after stealing an employee\u2019s credentials through malware. On Wednesday, the India-based startup informed affected customers of the incident via email, stating that the breach occurred on March 27 and involved a system used for internal analytics. The company said it detected the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":244053,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-244052","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/244052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=244052"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/244052\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/244053"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=244052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=244052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=244052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}