FEDERALSocial EngineeringHealthcarePhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICHEALTH_BASICLowActive
Hims & Hers Health, Inc.
bd_0cc210b877a07d46 · schema v1 · pii pii-v1
Full breach record for Hims & Hers Health, Inc. →Hims & Hers Health disclosed a cybersecurity incident in its 10-K filing. In early February 2026, an unauthorized third party gained access to systems via social engineering/phishing of two employees. The actor accessed customer service software, obtaining PII (names, emails, addresses) and potentially treatment category data for customers active between Feb 2025 and Feb 2026. EMRs were not accessed. The investigation is ongoing, and notifications are pending. The company does not believe the incident is materially impactful to financials.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3ace3aee1cea21e8California State AGfiled 2026-04-02(38d gap)Verified
- bd_af58dc468106a80bVermont State AGfiled 2026-04-02(38d gap)Verified
- bd_92ad67154a74fee8Texas State AGfiled 2026-04-06(42d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1773751/000177375126000022/hims-20251231.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 23, 2026
- Raw hash
- 943870e75487a388f7a57a21c0c60b9821e2ec6650a1615dcc331298e9b03355
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Hims & Hers Health, Inc.norm: hims hers health
- Domain
- hims.com
Victim entity
- Name
- Hims & Hers Health, Inc.norm: hims hers health
- Domain
- hims.com
Incident
- Discovered
- Feb 1, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- coordinating with law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.