All Breaches
February 4, 2026 Verified Sensitive Record Telehealth

Hims & Hers Zendesk 2026 Data Breach

The Hims & Hers Zendesk 2026 data breach is an incident in which the telehealth company confirmed unauthorized access to, or possible acquisition of, certain support tickets in a third-party customer-service platform. The company detected suspicious activity on February 5, 2026, and its investigation found that selected tickets were accessed or acquired between February 4 and February 7.

Hims & Hers determined on March 3 that some tickets contained personal information and notified affected people through a sample letter filed with California's Attorney General. Confirmed fields are names, contact information, and other unspecified personal data that may have appeared in the relevant support request. Because no person count was disclosed, pwnCount and totalRecords remain zero as an unknown total.

How Was the Incident Confirmed?

The company's regulatory letter says Hims & Hers secured its third-party customer-service platform and opened a scope investigation after detecting suspicious activity. The investigation confirmed that certain support requests were accessed or acquired without authorization. This statement classifies the event as a completed customer-data breach rather than only a possible cloud vulnerability.

BleepingComputer identified Zendesk as the affected platform and published the dates and data boundaries in the official notice. The report also cited source information connecting the attack to a broader campaign, an Okta account, and a named threat actor. Because the Hims & Hers regulatory letter did not confirm those technical attributions, LeakData adds no actor or definitive initial-access method.

What Information Was Affected?

According to the company, affected support tickets could contain names, contact information, and other personal data in the request, depending on the person. Because every component of “contact information” was not separately disclosed, LeakData does not assume that email, phone, or address appeared for everyone. Unspecified other content is represented by a broad support-ticket class rather than invented data types.

The nature of support tickets means a customer may have supplied free text or additional details while explaining a problem, but the company did not say prescriptions, diagnoses, treatment, or payment data was taken. Data classes remain at the level confirmed by the official notice. The record does not infer an entire customer profile or complete health history.

Medical Records and Doctor Messages

Hims & Hers explicitly said medical records and communications with doctors were not compromised in this incident. The breach is limited to certain requests in the customer-service platform; it did not affect the clinical-record system, provider conversations, or every component of a telehealth account. This boundary prevents automatic addition of health data based only on the company's sensitive business context.

A user could theoretically have typed health-related details into a support request, but the company did not confirm such a field. LeakData does not add medical records as a data class and assesses sensitivity from the verified customer-support context. The record can become more specific if a later company or regulatory update confirms particular health fields.

Why Is the Affected-Person Count Unknown?

The company confirmed notifications and personal information in some tickets but published no total number of users, customers, or tickets. Reports referring to millions of support tickets do not constitute a company-confirmed affected-person count. Ticket volume may also differ from unique people because one customer can open multiple requests.

LeakData therefore keeps pwnCount and totalRecords at zero; zero does not mean the incident involved no people or had no impact. The company's overall user base, revenue, and prescription volume are not used as substitutes for breach scope. Numeric fields can be updated if state filings or a completed forensic review publish a reliable person total.

Company Response and User Precautions

After detecting suspicious activity, Hims & Hers secured the customer-service platform, investigated the incident's nature and scope, and notified affected people. Eligible recipients were offered 12 months of complimentary credit monitoring. The public notice does not say that the platform's complete technical details or the attacker's identity were conclusively established.

Users should watch for unfamiliar emails, texts, and calls and verify links in messages posing as Hims & Hers support through the official application or known website. Account activity and credit reports may be monitored. This guidance addresses phishing and social-engineering risk; it does not mean exposure of medical records or financial data was confirmed.

How to Interpret This LeakData Record

This record establishes that unauthorized people accessed or acquired certain Hims & Hers support requests in a third-party customer-service platform between February 4 and February 7, 2026. Names, contact information, and other ticket-related personal data may have been involved. The people and ticket totals, fields present for each person, and full acquired-content volume remain unknown.

The verified boundary is customer-support tickets; medical records and doctor communications were unaffected. Zendesk was identified by independent reporting, but the attacker, Okta path, and bulk-ticket figure were not confirmed in the company letter. LeakData records the real third-party breach while preserving verified data limits and not converting reported technical claims into established fact.

0
Affected Accounts
3
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

3
Names
Contact information
Other personal data contained in selected support tickets

Additional Information

Added DateJuly 27, 2026
Breach DateFebruary 4, 2026
Domainhims.com
SourceUnauthorized access to or acquisition of customer support tickets
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information