Wellness wearable startup Ultrahuman confirmed that unauthorized actors breached its systems on March 27, gaining access to sensitive customer health data. The intrusion occurred after hackers compromised an employee’s credentials via a malware-infected laptop, allowing them to infiltrate an internal analytics tool.
Incident Response and Scope
The India-based company alerted affected users via email this past Wednesday. Ultrahuman officials stated that the security breach was detected within hours, prompting the team to immediately take the affected system offline and revoke all unauthorized access points.
According to the company, approximately 0.1% of its user base was impacted. While Ultrahuman declined to provide an exact headcount, based on its reported 700,000 monthly active users, the breach likely affected at least 700 individuals. The firm emphasized that no payment information, user passwords, production systems, or physical Ring devices were compromised during the event.
What We Know About the Data
Ultrahuman CEO Mohit Kumar noted that the startup delayed notifying users to conduct a thorough audit, ensuring they could accurately determine the scope of the exposure. The company confirmed in an official FAQ that the attackers held “read-only” access to the internal system. However, the startup has not yet confirmed whether any of the accessed data was exfiltrated from their servers.
The company has stopped short of defining exactly what constitutes “wellness data” in this context and has not disclosed whether they received any communications or ransom demands from the threat actors involved.
Context: The Risks of Health Tech
Founded in 2019, Ultrahuman is a major player in the metabolic health-tracking space, known for its Ring Air and the newly released Ring Pro. This incident underscores the growing privacy concerns surrounding health-tech firms. Like competitors such as Oura, these companies aggregate massive amounts of personal health metrics on centralized servers, creating high-value targets for hackers and raising questions about internal data accessibility protocols.
The startup, which has raised approximately $103 million from investors including Nexus Venture Partners and Steadview Capital, is currently working with regulators to address the fallout of the incident.
