The startup Ultrahuman reveals a health data leak that occurred on March 27, 2026. Hackers exploited an employee's credentials to access an internal database.
An infected laptop as an entry point
It was through a classic but effective vector that attackers managed to penetrate Ultrahuman's systems. An employee of the Indian startup was using a laptop compromised by malware designed to steal login credentials. This data allowed intruders to access an internal analysis tool, thus exposing well-being information belonging to some of the platform's users. The incident occurred on March 27, 2026, more than two months before the company publicly informed its users.
The company states that it detected the intrusion quickly and immediately took the affected system offline, while revoking all access. "Our security alerting systems detected the incident within hours, and we closed the vulnerability swiftly," said Mohit Kumar, founder and CEO of Ultrahuman, in a statement to TechCrunch. (Our security alerting systems detected the incident within hours, and we closed the vulnerability swiftly.)
What hackers could see
According to the official page published by Ultrahuman on its website, the attackers obtained "read-only" access to the compromised system. Specifically, the potentially exposed information includes account data, contact details, and transaction history. Passwords, bank card details, and payment information were not affected, nor were the production systems and the Ultrahuman Ring devices themselves.
"On March 27, 2026, we had a security incident, but the most important facts first: no passwords, card details, or payment data were involved, and we have found no evidence of misuse," Kumar stated in an email sent to affected users. (On March 27, 2026, we experienced a security incident, but the most important facts first: no passwords, card details, or payment data were involved, and we have found no evidence of misuse.)
The CEO described the exposure as similar to a lost order receipt found on the street: visible identification and contact information, but nothing financially sensitive. The company specifies that it has strengthened its internal control policies and endpoint security on employee devices following the incident.
The scale of the incident and the gray areas
According to figures released by Ultrahuman, approximately 0.1% of its users were affected. The startup had around 700,000 active users per month in March 2026, bringing the number of affected individuals to at least 700. The company did not dispute this calculation but declined to disclose a precise figure.
Significant gray areas remain. Ultrahuman did not indicate whether biometric data was actually exfiltrated or merely accessed, nor whether the attackers had contacted the company. The startup also did not clarify exactly what the term "well-being data" covers in this specific context, making it difficult to assess the real risk for affected users. The company also acknowledged delaying user notification while auditing the exact scope of the incident and identifying the specific data involved. The relevant regulators have been notified as part of this process.
The alert email sent to users urges them to remain vigilant against phishing attempts, a standard precaution after such incidents, as exposed contact data can be used for targeted phishing campaigns.
A structural issue for the entire sector
This incident goes beyond Ultrahuman's specific case and highlights an inherent vulnerability in the market for health wearables. Manufacturers of smart rings and watches, from Oura to Samsung and Fitbit, inherently centralize highly personal biometric data on their servers: sleep data, heart rate, heart rate variability, skin temperature, and menstrual cycle tracking. This centralization means that unauthorized access, whether from an employee, a government, or a malicious group, always remains technically possible.
Founded in 2019 in Bengaluru, Ultrahuman has gradually established itself in this competitive market thanks to its Ring Air, a direct competitor to the Oura Ring, and more recently with the Ring Pro, equipped with improved sensors and better battery life. The startup has raised approximately $103 million to date, with the support of investors such as Nexus Venture Partners, Steadview Capital, and Blume Ventures. The company claims a privacy-focused approach, a stance put to the test by this incident. It is worth noting that both Ultrahuman and Oura were already in opposition in 2024 in a patent infringement case before the U.S. International Trade Commission, a dispute that had highlighted certain questionable business practices of the Indian startup.
The trust of users in connected health platforms relies on these companies' ability to protect some of the most intimate data imaginable. This incident serves as a reminder that an internal analysis tool, often considered peripheral in a company's security architecture, can be a sufficient entry point to expose personal information on a large scale. Concerned Ultrahuman users would be well-advised to monitor for any fraudulent contact attempts in the coming weeks and to consult the official information page published by the company for details regarding their data.



No Comment! Be the first one.