DisclosureLens
FEDERALSocial EngineeringHealthcareTechnologyHealthcarePhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedDelayed DiscoveryPIIIdentity (basic)Health (basic)LowActive

Hims & Hers Health, Inc.

bd_0cc210b877a07d46 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 1, 2026

Filed

Feb 23, 2026

To disclose

22 days

Affected

Not disclosed

Linked

4 filings

Confidence

64%
Full breach record for Hims & Hers Health, Inc.

Hims & Hers Health disclosed a cybersecurity incident in its 10-K filing. In early February 2026, an unauthorized third party gained access to systems via social engineering/phishing of two employees. The actor accessed customer service software, obtaining PII (names, emails, addresses) and potentially treatment category data for customers active between Feb 2025 and Feb 2026. EMRs were not accessed. The investigation is ongoing, and notifications are pending. The company does not believe the incident is materially impactful to financials.

Incident timeline

undetected · 351 days
discovery → filing · 22 days

Feb 15, 2025

Begins

Feb 1, 2026

Discovered

Feb 23, 2026

Filed

vs. sector median

9 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 3 states

View merged incident ↗
SEC 10-K Item 1CFeb 23 · first · this page

Pattern: first filing Feb 23, last Apr 6 (TX) — a 42-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.