HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Hims & Hers Health, Inc.
bd_3ace3aee1cea21e8 · schema v1 · pii pii-v1
Full breach record for Hims & Hers Health, Inc. →Hims & Hers, Inc. disclosed that from February 4-7, 2026, unauthorized parties accessed customer service tickets on a third-party platform. The incident involved names, contact info, and potentially health-related data for a limited set of individuals. Hims & Hers secured the platform, notified law enforcement, and is offering 12 months of credit monitoring.
California clockDiscovered Feb 5, 2026 → Notified Apr 2, 202656d ✗ CA 30-day late8 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_af58dc468106a80bVermont State AGfiled 2026-04-02Verified
- bd_92ad67154a74fee8Texas State AGfiled 2026-04-06(4d gap)Verified
- bd_0cc210b877a07d46SEC 10-K Item 1Cfiled 2026-02-23(38d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621205
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2026
- Raw hash
- 2ab514c0638d639674db87e0e953887aa867df515a844a06d18cb4c95b021d09
Reporting entity
- Name
- Hims & Hers Health, Inc.norm: hims hers health
Victim entity
- Name
- Hims & Hers Health, Inc.norm: hims hers health
Incident
- Discovered
- Feb 5, 2026
- Materiality determined
- —
- Notification sent
- Apr 2, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementWill notify relevant regulators, as required
- Third party
- via third-party customer service platform
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- CA 30-day late · 56dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 5, 2026→ Notified: Apr 2, 202656d 30 calendar days CA 30-day late California Consumers notified: Apr 2, 2026→ AG copy submitted: Apr 2, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.