Hims & Hers Health disclosed a cybersecurity incident in its 10-K filing. In early February 2026, an unauthorized third party gained access to systems via social engineering/phishing of two employees. The actor accessed customer service software, obtaining PII (names, emails, addresses) and potentially treatment category data for customers active between Feb 2025 and Feb 2026. EMRs were not accessed. The investigation is ongoing, and notifications are pending. The company does not believe the incident is materially impactful to financials.