
Wearable health tech startup Ultrahuman says hackers accessed customer wellness data after stealing an employee’s credentials through malware, in an incident that the India-based company says was quickly contained but not fully disclosed to affected users until weeks later.
What Ultrahuman says happened
Ultrahuman told customers in an email on Wednesday that the breach took place on March 27 and involved a system used for internal analytics. The company said it detected the intrusion promptly, took the affected system offline, and revoked all access. In a statement to TechCrunch, Ultrahuman confirmed that the attackers used credentials stolen from an employee’s malware-infected laptop.
The company said the unauthorized access affected wellness data belonging to about 0.1% of users. Using Ultrahuman’s previously reported figure of roughly 700,000 monthly active users, that would amount to at least 700 customers. Ultrahuman did not dispute that estimate, but it declined to provide an exact count of affected customers.
What data was, and was not, affected
Ultrahuman said no passwords, payment information, production systems, or Ultrahuman Ring devices were compromised. The company also said the attackers gained only “read-only” access to the affected system, according to an FAQ posted on its website.
However, the company declined to say whether its investigation determined if any customer data was exfiltrated. It also did not define exactly what it considers “wellness data,” leaving open questions about which user details may have been visible to the attacker.
According to the report, Ultrahuman has not disclosed whether it received any communication from the hackers, and it has not said whether the incident involved any ransom demand or other contact from the threat actor.
How the company described its response
Ultrahuman CEO Mohit Kumar said the company’s alerting systems spotted the intrusion within hours and that it moved quickly to close the vulnerability. “Our security alerting systems detected the incident within hours, and we closed the vulnerability swiftly,” Kumar told TechCrunch.
Kumar also said the startup was notifying regulators and had delayed informing affected users while it audited the full scope of the incident and determined what data had been affected. That timeline matters because the breach occurred on March 27, while customer notice was sent on Wednesday, meaning the company waited weeks before directly alerting users.
While Ultrahuman says it detected the issue quickly and limited access, the episode underscores how even a short-lived intrusion can expose sensitive health-related information if internal systems contain customer records.
Why the incident matters for wellness platforms
Ultrahuman’s breach highlights a broader reality for wellness-tracking companies: data collected through rings and other devices often lives on company servers, where it can be accessible to employees with legitimate permissions and, in some cases, to governments or malicious hackers if systems are compromised.
That data model is particularly sensitive because it can reveal highly personal information about sleep, activity, recovery, and other health indicators. Even if no payment data or device firmware is touched, unauthorized access to wellness metrics can still create privacy risks for customers who expect their wearable data to remain tightly protected.
The company’s disclosure comes amid growing scrutiny of consumer health technology firms, which increasingly collect detailed biological and behavioral information while also relying on cloud services and internal analytics tools to process it. In this case, the access path appears to have been an employee account compromised through malware, rather than an attack on customer devices themselves.
About Ultrahuman and its products
Founded in 2019, Ultrahuman sells smart rings and metabolic health-tracking devices that let users monitor metrics such as sleep, activity, and recovery. The company is best known for its Ring Air, which competes with the Oura Ring, and it recently introduced the Ring Pro with upgraded sensors and battery life.
Ultrahuman has grown into one of the more visible players in the wearable wellness category, and its products are aimed at users who want detailed insights into their daily health patterns. That positioning makes the security of its internal analytics systems especially important, since such systems may hold aggregates or individual-level data used to generate user-facing metrics and insights.
Funding and investor backdrop
Ultrahuman counts Nexus Venture Partners, Steadview Capital, and Blume Ventures among its investors. Per Tracxn, the startup has raised around $103 million to date. The company’s scale and funding profile help explain why the incident has drawn attention: a fast-growing consumer health company with a large user base and significant investor backing is expected to maintain strong controls around any data tied to personal health.
At the same time, Ultrahuman’s disclosure suggests the breach was limited to a specific internal system rather than a broad compromise of the company’s product infrastructure. Still, the company has not answered every question about what was accessed or whether anything was copied out of the environment.
Open questions remain
Several details remain unresolved. Ultrahuman has not said precisely what information falls under “wellness data,” whether any records were actually removed from the system, or whether the company has seen evidence of misuse. It has also not shared whether law enforcement was involved, beyond saying it was notifying regulators.
For customers, the most important takeaway is that the incident did not, according to Ultrahuman, affect passwords, payment details, production systems, or devices. But for privacy purposes, the fact that employee credentials were stolen and used to reach a system containing user wellness information is still significant, especially in a sector built on trust and sensitive personal data.
As the wearable market continues to expand, breaches like this one are likely to keep focus on the internal tools and employee accounts that sit behind consumer health products. Those systems may not be visible to users, but they can hold enough information to make them a valuable target for attackers.
Source: Original report
Was this helpful?
Last Modified: July 7, 2026 at 9:21 pm
3 views

