Hims & Hers hack exposes customer support data in February breach

Hims & Hers, a leading telehealth provider, has reported a significant breach in its customer support system.

2 min readTechCrunch
Hims & Hers hack exposes customer support data in February breach

The Hims & Hers breach is a reminder that customer support systems are often the weakest link in data security, and the fallout from this incident will be felt far beyond the exposed ticket contents. When hackers stole support data over several days in February, they didn't just grab names or order histories; they accessed the kind of sensitive back-and-forth that reveals how people talk about their health. For a telehealth company, that is not a small distinction.

What this means for you, the user, is that the data stolen is not a random collection of logins. It is a map of your interactions, your concerns, and potentially your medical history as shared through support channels. The practical takeaway is uncomfortable: you should assume that any detail you have ever typed into a customer service window is now in the hands of someone who does not have your best interests in mind. That changes how you should approach password resets, phishing emails, and even unsolicited phone calls claiming to be from your provider.

This incident also exposes a broader truth about the state of digital health. Companies can invest heavily in encryption and app security, yet leave the front door open through a support ticketing system that was never designed to hold such sensitive context. The breach did not require a sophisticated exploit or a nation-state actor; it required a few days of access to a system that should have been monitored like a vault. That is not a failure of technology, but a failure of prioritization.

The response from Hims & Hers will matter, but so will your own next steps. If you have used their support in the past, treat any follow-up communication with skepticism. Verify requests through official channels, and do not assume that a data breach notification is the last you will hear of it. The concrete point is this: your health data is a permanent record, and once it is out, no apology will put it back. The question is not whether this breach will have consequences, but whether you are prepared for the ones that are already in motion.

From TechCrunch

The U.S. telehealth giant says hackers stole customer support ticket data over the course of several days in February.

Read the original at TechCrunch