Categories: Tech & Ai

Telehealth giant Hims & Hers says its customer support system was hacked


Hims & Hers, the telehealth company that sells weight-loss drugs and sexual health prescriptions, has confirmed a data breach affecting its third-party customer service platform.

The healthcare company said in a data breach notice filed with the California attorney general’s office on Thursday that the hackers stole data about user requests sent to the company’s customer support team. The company said hackers broke into its third-party ticketing system between February 4 and February 7 and stole reams of support tickets, which contained personal information submitted by customers.

The data breach notice said the hackers took customer names and contact information, as well as other unspecified personal data that Hims & Hers left redacted in the letter.

Although the company says customer medical records were not affected by the breach, the nature of customer support systems means that the data may contain sensitive information about a person’s account, personal information, and healthcare.

It’s not yet known how many individuals had personal information compromised in the hack. Under California law, companies are required to disclose data breaches involving 500 or more state residents.

Jake Martin, a spokesperson for Hims & Hers, told TechCrunch in a statement the company was hit by a social engineering attack, in which hackers trick employees into granting access to their systems. The spokesperson said the stolen data “primarily included customer names and email addresses.” The company did not say what specific types of data were taken, when asked by TechCrunch.

The company would not say if it has received any communication from the hackers, such as a demand for money.

In recent months, customer support and ticketing systems have become rich targets for financially motivated hackers, who have raided databases containing customer information and extorted companies into paying a ransom.

Last year, Discord had a data breach that affected its customer support ticketing system and exposed the government-issued IDs of around 70,000 people who had submitted their driver’s licenses and passports to the company to verify their age.



Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Ceasefire odds drop to 1.8% as Iran continues missile attacks on Israel

Israel’s missile defenses stopped most Iranian missiles, but Iran continues sporadic attacks. The odds of…

21 minutes ago

NFL’s Billion-Dollar Sportsbook Partnerships Expire With No Replacement as League Faces Microbetting Lawsuit – iGaming Bitcoin News

Genius Sports Data Pricing Dispute Stalls Negotiations as Public Health Advocates Sue League Over In-Game…

31 minutes ago

Three Macro Signals Align for Altcoins: But Is It Alt Season?

The ALT/BTC chart has printed four consecutive green MACD bars for the first time in…

1 hour ago

Patch Now: Chrome Flaw Under Active Attack, Google Confirms

Google patches 21 Chrome vulnerabilities, including an actively exploited zero-day flaw that could enable code…

2 hours ago

PLDT and Smart to Ban Roblox Upon Order

Telecommunications providers PLDT Inc. and Smart Communications Inc. have confirmed their preparedness to block access…

2 hours ago

Uniswap brings v2, v3 and v4 to Consensys’ Linea zkEVM

Uniswap has deployed v2, v3 and v4 on Consensys’ Linea zkEVM, bringing its full DEX…

2 hours ago