Hims & Hers Hit by Data Breach via Zendesk Vulnerability

Hims & Hers Hit by Data Breach via Zendesk Vulnerability

Health and wellness company Hims & Hers has alerted customers to a potential data breach following a security incident affecting its third-party customer support platform, Zendesk. The breach, which occurred between April 10 and April 17, 2024, may have exposed sensitive customer information.

According to Hims & Hers, the unauthorized access was limited to specific customer support interactions. The compromised data could include names, contact details (email addresses and phone numbers), dates of birth, and in some cases, treatment information or prescription details. The company emphasized that financial information and Social Security numbers were not affected. The incident underscores the critical importance of supply chain security, as a vulnerability in a trusted vendor can have direct and significant repercussions for their clients.

Zendesk has since stated that it has implemented measures to address the vulnerability and prevent further unauthorized access. Hims & Hers is advising affected customers to remain vigilant against potential phishing attempts and to monitor their accounts for any suspicious activity. This event serves as a stark reminder for organizations to rigorously vet their third-party vendors and to maintain robust data protection protocols across their entire digital ecosystem.

What This Means For You

  • Data exposure reported โ€” check if your organization or users are affected.
๐Ÿ”Ž
Is your vendor affected? Start hunting now. Search by organization or domain, set watchlist alerts, and get notified when your third parties are compromised.
Open Intel Bot โ†’

Related coverage

FTC Warns 12 Major Tech Firms Over Take It Down Act Violations

The Federal Trade Commission (FTC) has issued warnings to 12 prominent technology companies for alleged violations of the Take It Down Act. This legislation mandates...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM

Ukraine Probes Teen Suspect in US E-commerce Cyber Theft

Ukrainian authorities are investigating a teen suspect in a cyber theft scheme targeting online shoppers in California, according to The Record by Recorded Future. This...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM

Discord Enables End-to-End Encryption by Default

Discord has begun migrating all users to end-to-end encryption (E2EE) by default, a significant move for a major communication platform. This decision stands in stark...

threat-inteldata-breachgovernment
/SCW Research /MEDIUM