OTHER

Ultrahuman Reveals Hackers Accessed Customer Wellness Data via Internal Tool

Ultrahuman, a startup specializing in wearable health technology, has revealed that hackers accessed customers’ wellness data by leveraging an employee’s credentials through malware.

On Wednesday, the company, based in India, notified impacted individuals via email about the breach that occurred on March 27, which involved a system used for internal analytics. Ultrahuman reported that it promptly detected the intrusion, disconnected the affected system, and revoked all access.

Established in 2019, Ultrahuman provides smart rings and metabolic health-tracking devices that assist users in monitoring metrics such as sleep, activity, and recovery. The startup is especially known for its Ring Air, which competes against the Oura Ring, and has recently introduced the Ring Pro, equipped with upgraded sensors and longer battery life.

In a confirmation of the breach, Ultrahuman informed TechCrunch that the attackers exploited credentials collected from an employee’s laptop infected with malware, granting access to wellness data for about 0.1% of users.

With the company’s earlier reports indicating roughly 700,000 monthly active users, this suggests that at least 700 customers had their health data accessed. While Ultrahuman did not dispute this number, it chose not to disclose the precise figure of affected customers. The company reassured that no passwords, payment information, production systems, or Ultrahuman Ring devices were infiltrated.

“Our security alert systems detected the incident within hours, and we quickly addressed the vulnerability,” stated Ultrahuman CEO Mohit Kumar in correspondence with TechCrunch.

Kumar mentioned that the startup is informing regulators and had delayed notifying affected customers while conducting a thorough assessment of the incident to determine the specific data that was compromised.

Ultrahuman did not provide any information regarding whether communication was received from the hackers involved in the breach and did not elaborate on what exactly is included in “wellness data.” This incident highlights how wellness tracking startups like Ultrahuman and Oura manage user data in a way that allows access by employees, governments, and malicious entities.

According to an FAQ on its website, the startup stated that the threat actor achieved “read-only” access to the affected system. However, the company did not confirm whether its investigation showed any customer data was downloaded.

Ultrahuman has prominent investors, including Nexus Venture Partners, Steadview Capital, and Blume Ventures. To date, the startup has raised approximately $103 million, according to Tracxn.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.