[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb5i975ns8o45":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":18,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":26,"seoTitle":27,"seoTitleEn":8,"seoDescription":27,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"6a6f8009efd19e3a0c3a34a9","Ultrahuman2026","Ultrahuman 2026 Data Breach","ultrahuman-2026","ultrahuman.com","2026-03-27T00:00:00.000Z","2026-08-02T17:36:08.782Z","Compromised employee credentials used to access an internal analytics system","https:\u002F\u002Fwww.ultrahuman.com\u002Flegal\u002Fnotice-march-2026\u002F",[14,16,17],"https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-624394","https:\u002F\u002Ftechcrunch.com\u002F2026\u002F06\u002F03\u002Fultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool\u002F",null,"unknown","people","Unknown",[23,24,25],"Contact information","Purchase history","Personal health data","\u003Cp>Ultrahuman is an India-based health technology company that develops smart rings and metabolic health products. The company disclosed that an unauthorized person accessed one of its internal analytics systems on March 27, 2026.\u003C\u002Fp>\u003Cp>The accessible information varied by person and included contact and account details, order and transaction history, and some product-use fitness data for a smaller group of users. The total number of affected people has not been publicly disclosed.\u003C\u002Fp>\u003Ch2>Confirmed incident sequence\u003C\u002Fh2>\u003Cp>The unauthorized person obtained read-only access to the internal analytics tool. Ultrahuman said it detected the incident within hours, took the system offline, and revoked access.\u003C\u002Fp>\u003Cp>According to information the company provided to TechCrunch, the employee credentials used for access were stolen from a malware-infected laptop. Production systems, the Ultrahuman app, and Ring devices were not affected.\u003C\u002Fp>\u003Ch2>Affected data and exclusions\u003C\u002Fh2>\u003Cp>The public notice confirms contact and account details together with order or transaction history. Fitness data associated with product usage and purchases was also visible for some users, but individual wellness metrics were not publicly itemized.\u003C\u002Fp>\u003Cp>Ultrahuman said passwords, full payment-card numbers, CVVs, and bank credentials were not accessible. Those fields are not added to the record, and the company did not report a breach of users' social sign-in provider accounts.\u003C\u002Fp>\u003Ch2>Health and behavioral-data risks\u003C\u002Fh2>\u003Cp>Order and contact history can make fraudulent delivery, warranty, subscription, or support messages more convincing. Attackers can use genuine product context to encourage a user to open a link or disclose additional information.\u003C\u002Fp>\u003Cp>Fitness information can create sensitive context about daily habits, but the notice does not identify the specific metrics that were visible. Sleep, heart-rate, glucose, or any other individual health field should not be assumed to have been exposed.\u003C\u002Fp>\u003Ch2>Steps users can take\u003C\u002Fh2>\u003Cp>Ultrahuman directly emailed affected accounts on or after June 2, 2026. Verify a notice through the company's official incident page and confirmed contact address instead of following a link in an unexpected message.\u003C\u002Fp>\u003Cp>Because Ultrahuman does not store an Ultrahuman password and uses Google, Apple, or Facebook sign-in, the incident does not directly require changing an Ultrahuman password. Users should still enable two-step verification with their sign-in provider and review active sessions.\u003C\u002Fp>\u003Ch2>Count and event boundaries\u003C\u002Fh2>\u003Cp>The company said the group whose fitness data was visible represented about 0.1% of users; that percentage is not the total number of affected accounts. An estimate of roughly 700 people derived from monthly active users is not an official total and is not used for this record.\u003C\u002Fp>\u003Cp>Read-only access means information could not be modified; it does not mean the data could not be viewed or exported. Ultrahuman reported no evidence of publication or misuse but did not confirm whether customer data was exfiltrated.\u003C\u002Fp>\u003Ch2>How to interpret a result\u003C\u002Fh2>\u003Cp>\u003Cstrong>A positive match\u003C\u002Fstrong> means the queried email address appears in a dataset associated with this event; it does not prove that fitness data or every listed field belongs to that person. The individual notification email provides the most specific scope.\u003C\u002Fp>\u003Cp>A negative result does not prove that a person was unaffected. Anyone who received an official notice should review the categories in that message regardless of the search result and remain cautious of Ultrahuman-themed phishing.\u003C\u002Fp>","","Ultrahuman's internal analytics system was accessed on March 27, 2026. Contact, order-history, and some fitness data were affected.","https:\u002F\u002Fwww.ultrahuman.com\u002Flogo.png",false,{"name":32,"sector":33,"country":34,"website":10,"websiteArchiveUrl":27,"websiteStatus":35,"websiteCheckedAt":12},"Ultrahuman","Health Technology","India","active"]