Hims & Hers warns of data breach after Zendesk support ticket breach
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内,并且不需要特定的开头。首先,我得仔细阅读这篇文章,了解主要内容。 文章主要讲的是Hims & Hers Health这个美国远程医疗公司遭遇了数据泄露。他们通过第三方客服平台处理支持请求,结果这些请求被黑客窃取了。泄露的时间是在2026年2月初,持续了几天。泄露的信息包括姓名、联系方式等,但没有涉及医疗记录或医生沟通内容。 接下来,文章提到这次攻击是由ShinyHunters勒索团伙实施的,他们利用Okta SSO账户入侵了Zendesk平台,窃取了数百万的支持请求。公司现在为受影响的用户提供一年的免费信用监控服务,并建议用户提高警惕。 此外,文章还提到之前有其他公司也因为Zendesk被入侵导致数据泄露的情况。 现在我要把这些信息浓缩到100字以内。需要包括公司名称、事件发生的时间、数据泄露的内容、攻击者是谁、使用的方法以及公司的应对措施。 可能的结构是:Hims & Hers Health在2026年2月遭遇数据泄露,第三方客服平台的支持请求被窃取,包含个人信息但无医疗记录。攻击者利用Okta SSO入侵Zendesk。公司提供信用监控服务,并提醒用户注意诈骗。 这样大概可以控制在100字左右。 </think> Hims & Hers Health在2026年2月遭遇数据泄露,第三方客服平台的支持请求被窃取,包含个人信息但无医疗记录。攻击者利用Okta SSO入侵Zendesk。公司提供信用监控服务,并提醒用户注意诈骗。 2026-4-3 17:45:16 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Hims and Hers pills

Telehealth giant Hims & Hers Health is warning that it suffered a data breach after support tickets were stolen from a third-party customer service platform.

Hims & Hers is an American telehealth company specializing in the direct-to-consumer healthcare space, providing subscription-based treatments for hair loss, ED, mental health, skincare, weight loss, and other conditions or needs.

It is one of the most successful U.S. brands in the online pharmacy and telehealth space, with strong marketing presence, and annual revenues close to $1 billion.

According to a sample of the notification shared with the authorities in California, the data breach occurred in early February 2026.

"On February 5, 2026, Hims & Hers, Inc. became aware of suspicious activity affecting our third-party customer service platform," reads the letter sent to impacted individuals.

"We promptly took steps to secure our customer service platform and initiated an investigation into the nature and scope of the potential security incident."

"The investigation determined that from February 4, 2026, to February 7, 2026, certain tickets sent to our customer service team were accessed or acquired without authorization."

Following an internal investigation, the company determined, on March 3, that hackers had accessed support tickets that, in some cases, contained personal information.

The exposed information may include names, contact information, and other unspecified data, likely related to the support request submitted in each case.

The company underlined that no medical records or doctor communications were compromised in this incident.

While the company did not share further details, BleepingComputer learned last month that the ShinyHunters extortion gang conducted the breach.

The data was stolen as part of a widespread campaign in which threat actors compromised Okta SSO accounts to gain access to third-party cloud storage services and SaaS platforms to steal data.

In this particular attack, BleepingComputer was told that the threat actors used the Okta SSO account to access the His and Hers Zendesk instance, where they stole millions of support tickets.

The company is now offering 12 months of free credit monitoring services to all impacted individuals.

Customers are also encouraged to maintain heightened vigilance against unsolicited communications that may contain phishing or social-engineering lures. Also, they are advised to review account statements and monitor credit reports for suspicious activity.

BleepingComputer has reached out to the firm to request more information about the incident and how many customers have been impacted, but we have not heard back by publication time.

Two recent high-profile customer support security breaches that led to client data breaches are those of DIY store chain ManoMano in February and Crunchyroll in March. In both these cases, the compromised platform was Zendesk.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/
如有侵权请联系:admin#unsafe.sh