Hackers Access Contact Details Of Ultrahuman Users Via Internal Tool
Ultrahuman said a March 27 breach let an unauthorised party access some user contact and account details through an internal analytics system.
Intelligence analysis by GPT-5.4 Mini

Ultrahuman told affected users that attackers got read-only access to an internal system after credentials were stolen from an employee laptop. The company says password, payment and core wellness data were not leaked, but contact, account, order and transaction details were accessed.
A thief got into one of Ultrahuman’s office computer systems and could look at some customer details, like contact and order records, but could not change them. It is like someone peeking through a window into a filing cabinet instead of stealing the whole cabinet.
Analysis
What happened
Ultrahuman said it suffered a cybersecurity incident on March 27, when an unauthorised third party got read-only access to one of its internal analytics systems. Because the access was read-only, the company said the system did not allow the attackers to modify or delete data.
What data was exposed
In its email to impacted customers, Ultrahuman said the breach did not leak critical information such as passwords, payment information or wellness data. But the company also said attackers did access user information including contact details, account details, and order and transaction history. Ultrahuman told TechCrunch that the compromise came through credentials stolen from a malware-infected employee laptop, and that the affected wellness data belonged to about 0.1% of users.
The article says that translates to at least 700 customers, based on earlier reports that Ultrahuman has around 7 lakh monthly active users.
What Ultrahuman says it did
The company said it took the affected system offline and revoked access. It also said it has hardened security on employee devices, increased the frequency of access audits, and deployed anomaly detection on internal systems. Ultrahuman added that it has been monitoring public and other internet channels for signs that the accessed information was published or misused, and said it had not found evidence of that so far.
Wider context
The breach comes while Ultrahuman is trying to rebuild momentum in its biggest market, the US, after a patent dispute with Oura led to an import ban. The company also recently reported profitability in FY25, with revenue rising sharply. The security incident does not change those business numbers, but it does add another trust and compliance challenge for a startup that handles sensitive personal health-related information.
Key points
- Ultrahuman said an unauthorised third party accessed an internal analytics system on March 27.
- The company said the access was read-only and the system could not be used to modify or delete data.
- Hackers reportedly reached the system using credentials stolen from a malware-infected employee laptop.
- Ultrahuman said contact, account, order and transaction details were accessed, but passwords and payment data were not leaked.
- The company says it has taken the system offline and tightened internal security controls.
Ultrahuman says it cut off access quickly, hardened employee devices, and added extra checks to spot unusual activity. If those changes hold up, the company could reduce the chance of a repeat incident and reassure users that the breach was contained.
Even with read-only access, the incident shows that stolen employee credentials can expose sensitive customer information. If users lose trust or regulators scrutinize the breach further, the company could face more reputational damage on top of its existing US market pressures.


