Wearable health-tech startup Ultrahuman disclosed a data breach that occurred on March 27, in which hackers used credentials stolen from a malware-infected employee laptop to access an internal analytics system. Wellness data belonging to approximately 0.1% of users — roughly 700 customers based on the company's ~700,000 monthly active users — was accessed. No passwords, payment data, or production systems were compromised. The threat actor had read-only access, but Ultrahuman declined to confirm whether data was exfiltrated. The company detected the intrusion within hours, took the system offline, and is notifying regulators. The incident raises broader concerns about how wellness tracker companies store sensitive health data in ways accessible to employees, governments, and malicious actors.

2m read timeFrom techcrunch.com
Post cover image
99 Impressions