LIVE NEWS
  • From threats to civilization to a ceasefire: The week in Washington
  • GAO report shows enforcement gap on illegal vapes
  • Epic is reportedly building an extraction shooter for Disney
  • What the Cease-Fire Means for Iran
  • This handy electric screwdriver is now 50% off – here’s where to snag the deal
  • Optimized afforestation reduces flood risk and limits water loss in Europe
  • Inflation surges to highest in nearly two years : NPR
  • Operation Overflow: How to break Iran’s grip over the Strait of Hormuz
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Hims Breach Exposes the Most Sensitive Kinds of PHI
Cybersecurity

Hims Breach Exposes the Most Sensitive Kinds of PHI

primereportsBy primereportsApril 10, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Hims Breach Exposes the Most Sensitive Kinds of PHI
Share
Facebook Twitter LinkedIn Pinterest Email


The telehealth company Hims & Hers Health, more commonly known as Hims, suffered a data breach via its third-party customer support platform. Due to the ultra-sensitive nature of some Hims products, customers could be at risk of some seriously embarrassing fallout.

Have you called a customer support line any time since the COVID-19 pandemic ended and heard an automated voice message say, “We’re experiencing a higher than normal call volume…” regardless of the day and time of your call? While organizations gradually have been replacing human customer service workers with bots and calling it “revolutionary,” they’ve been taking an equally penny-pinching approach to securing their customer service stacks online.

Cybercriminals have been targeting such platforms in recent years, and in the case of Hims, a threat actor gained access to customer support tickets that contained a potentially large amount of customers’ uttermost sensitive personal health information (PHI). The infamous ShinyHunters group claimed responsibility for the attack, according to a BleepingComputer report last week, but those claims could not be verified.

Related:Fraud Rockets Higher in Mobile-First Latin America

“This isn’t just a data breach — it’s a breakdown in the customer relationship,” says Baker Johnson, chief business officer at UJET. “When someone reaches out for support, especially in healthcare, that’s a moment of trust. They reached out for help and instead had their trust compromised. That changes how they engage — and once that hesitation sets in, loyalty is already at risk.”

What Happened to Hims Customer Data?

In a visibly self-refuting breach disclosure with the Vermont Attorney General’s Office, Hims reported having first become aware of suspicious activity targeting its customer service platform on Feb. 5. The company said it “promptly took steps to secure” the affected service, but those steps didn’t have such a prompt impact, as hackers maintained access from Feb. 4 to Feb. 7. In that time, “certain tickets” from customers seeking product support were nabbed by unauthorized actors.

It took a month for the company to determine that those support tickets contained names and unspecified medical information belonging to “a limited set” of affected customers. (A company representative told Dark Reading’s sister publication, Cybersecurity Dive, that email addresses were also impacted.) Another month later, the company began informing those affected customers. Hims did not say which third-party support platform it uses.

Dark Reading reached out to Hims, but didn’t get a response by the time of publication.

Related:Automated Credential Harvesting Campaign Exploits React2Shell Flaw

For Johnson, Hims is just the latest example of an industry-agnostic trend. “This is a design problem. Customer service is now one of the richest sources of personal data in the business, but it’s still managed across a patchwork of disconnected systems; recordings here, transcripts there, workflows somewhere else. That fragmentation is what creates risk,” he says.

Is Embarrassing PHI at Risk?

As the old story goes, Hims is now offering impacted customers a year of free credit monitoring, and a few paragraphs worth of guidance about identity protection.

The threat of identity theft, however, is hardly the only issue Hims customers now face. Between lascivious billboards and incessant podcast advertising, Hims has built its brand around the kinds of medical issues that people fear talking about the most: erectile dysfunction, balding, obesity, and mental health. 

Not only does it specialize in the extra sensitive, but the company markets largely to younger demographics — men and women at times in their lives when these issues carry extra stigma. With that in mind, if attackers obtained anything beyond basic personally identifying information (PII) from Hims — and even with that alone, potentially — it could empower them to blackmail individuals to a level beyond what leaks of general PHI typically allow.

Related:Not Toying Around: Hasbro Attack May Take ‘Weeks’ to Remediate

Dark Reading could not find evidence that ShinyHunters or any cybercriminal group has leaked the Hims data yet, though the extortion group has a history of leaking stolen data when its victims don’t pay up. 

For organizations that manage lots of third-party software platforms, “The path forward is designing experiences where data doesn’t sit scattered across systems in the first place, but where it moves securely, stays within trusted environments, and only exists as long as it’s needed,” UJET’s Johnson says. “Because in the end, security isn’t a feature of the experience. It’s what makes the experience trustworthy.”



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleStayed in Balcony Cabin on Norwegian Cruise Line Luna Ship: Review
Next Article Etherealize Say AI Will Fuel Ethereum Supply Shock: Here’s Why and Next Coin to Pump
primereports
  • Website

Related Posts

Cybersecurity

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

April 10, 2026
Cybersecurity

Russia Hacked Routers to Steal Microsoft Office Tokens – Krebs on Security

April 10, 2026
Cybersecurity

Apple Intelligence AI Guardrails Bypassed in New Attack

April 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • From threats to civilization to a ceasefire: The week in Washington
  • GAO report shows enforcement gap on illegal vapes
  • Epic is reportedly building an extraction shooter for Disney
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.