TL;DR: Between February 4 and 7, 2026, ShinyHunters broke into Hims & Hers’ Zendesk customer support system by compromising an Okta single sign-on account. They stole millions of support tickets: tickets where customers described their health conditions, asked about medications, and discussed prescriptions. No medical records or payment data were exposed, but the stolen conversations paint an intimate picture of each person’s health. The company waited until April 2 to file a breach notice with the California Attorney General, nearly two months after the attack. Law firms are already circling. If you’ve ever contacted Hims & Hers support, assume your conversation is compromised.
A Telehealth Company’s Worst Nightmare
Hims & Hers isn’t some niche startup. It’s a $2.35 billion-a-year telehealth company with over 2.5 million active subscribers.[1] People use it to get prescriptions for hair loss, erectile dysfunction, weight loss drugs, mental health medications, and skin care treatments. The kind of stuff you might not tell your closest friends about. The kind of stuff you definitely wouldn’t want hackers reading.
On February 5, the company detected suspicious activity on its Zendesk customer service platform.[2] By the time they locked the door, ShinyHunters had already been inside for at least a day, from February 4 through February 7, vacuuming up customer support tickets at scale.
The attack vector? The same one ShinyHunters has used to breach 100+ companies since late 2025: compromising an Okta SSO account. One stolen credential. One login. Access to everything the support platform could see.[3]
What Was in Those Tickets
Hims & Hers confirmed the stolen data includes:[2][4]
- Full names
- Email addresses
- Phone numbers and mailing addresses
- Order reference numbers and status updates
- Customer service correspondence
That last bullet is the one that matters most. When you contact a telehealth company’s support team, you’re not asking about a delayed Amazon package. You’re asking about your medication dosage. You’re describing side effects. You’re explaining why you need a prescription changed. These tickets contained “medication inquiries, prescription questions, and descriptions of health conditions,” according to reporting from TechBuzz.[5]
The company insists that “medical records, diagnostic details, and prescription data” stored in their primary healthcare systems weren’t touched.[4] That’s true as far as it goes. But the distinction between a medical record and a support ticket where someone describes their depression symptoms while asking about an SSRI refill is a difference that matters to lawyers, not to the person whose words just showed up on a dark web forum.
Same Crew, Same Trick, New Victim
If ShinyHunters sounds familiar, it should. We’ve been tracking this group for months. They’re responsible for:
- The 100+ company Okta SSO campaign: voice-phishing employees to steal single sign-on credentials
- The European Commission breach: 340GB of EU institutional data stolen
- Panera Bread: 5 million customer records
- Infinite Campus: 11 million student records
- Telus Digital: 1 petabyte of data including FBI background check records
The playbook is the same every time. Find an employee at the target company. Call them pretending to be IT support. Walk them through a fake Okta login page. Steal the SSO credential. Use it to pivot into whatever cloud service (Zendesk, Salesforce, Snowflake) that credential can reach. Exfiltrate everything. Demand a ransom. Dump the data when the company refuses to pay.
Google’s Mandiant team has been tracking this campaign since it accelerated in late 2025. It hasn’t slowed down.
Two Months of Silence
The breach happened February 4–7. Hims & Hers detected it February 5. The filing with the California Attorney General? April 2.[2]
That’s 56 days.
The company says it “launched an internal investigation and brought in cybersecurity experts” after detection.[4] An internal investigation determined on March 3 that hackers had accessed support tickets containing personal information.[2] Even measuring from March 3, that’s 30 days to get from “we know data was exposed” to “we’re telling regulators.”
Under California’s data breach notification law (Cal. Civ. Code § 1798.82), companies must notify affected residents “in the most expedient time possible and without unreasonable delay.” Whether 30 to 56 days qualifies as “expedient” is exactly the kind of question class action attorneys love to litigate.
And they already are. At least two law firms, including Edelson Lechtzin LLP, publicly announced investigations into the breach within days of the California AG filing.[6]
The Telehealth Trust Problem
This breach highlights a structural weakness in how telehealth companies handle data. Your medical records sit in HIPAA-regulated systems with strict access controls. But your conversations with customer support? Those live in Zendesk. Or Salesforce. Or whatever third-party SaaS platform the company picked because it scales well and has good analytics.
Those platforms aren’t designed to protect health information. They’re designed to manage support tickets. And when you message support saying “my anxiety medication isn’t working, can I switch to something stronger,” that message lives in a system built for tracking customer satisfaction metrics, not safeguarding protected health information.
HIPAA covers medical records. It doesn’t always cover the Zendesk ticket where you described the same symptoms to a support agent. That’s a gap that 2.5 million Hims & Hers subscribers just fell through.
What to Do If You’re a Hims & Hers Customer
Assume your support conversations are compromised. If you’ve ever contacted customer service, about an order, a prescription, a question about a medication, act as if that conversation is now in someone else’s hands.
- Activate the free credit monitoring. Hims & Hers is offering 12 months of complimentary monitoring.[4] Take it. It’s the bare minimum.
- Watch for targeted phishing. ShinyHunters now has your name, email, phone number, and detailed knowledge of what medications or treatments you use. Expect convincing phishing emails that reference your specific health situation. Don’t click links in messages about your Hims & Hers account.
- Change your Hims & Hers password. Enable two-factor authentication if you haven’t already. Use a unique password not shared with any other service.
- Monitor your accounts. Check bank and credit card statements for unusual charges. Review your credit reports at annualcreditreport.com.
- Consider a credit freeze. If your name, address, and date of birth were in those tickets, a credit freeze prevents anyone from opening accounts in your name. It’s free at all three bureaus: Equifax, Experian, TransUnion.
ShinyHunters Aren’t Slowing Down
Hims & Hers is the latest victim in a campaign that has now breached over 100 organizations. ShinyHunters doesn’t exploit exotic zero-day vulnerabilities. They call employees on the phone. They send convincing fake login pages. They exploit the weakest link in every company’s security: people.
As long as companies rely on SMS-based or app-based MFA instead of hardware security keys (FIDO2), as long as third-party SaaS platforms sit behind a single SSO credential without additional access controls, this will keep happening.
The only question is how much health data, financial data, and personal data gets harvested before companies actually fix the authentication problem.
Sources
- Hims & Hers Health Q4 and Full Year 2025 Financial Results
- News4Hackers: Hims & Hers Experiences Data Breach Following Zendesk Support Ticket Incident
- Cloaked: Were You Affected by the Hims & Hers Data Breach?
- World Today News: Hims & Hers Health Suffers Data Breach via Third-Party Platform
- TechBuzz: Hims & Hers Confirms Customer Support Breach in February
- GlobeNewsWire: Edelson Lechtzin LLP Investigates Hims & Hers, Inc. Data Breach
Published: April 5, 2026