Indian wearable health tech startup Ultrahuman has suffered a data breach after hackers used malware-stolen credentials on 27 March to access customer wellness data via an internal analytics tool.
On Wednesday, the Bengaluru-based startup informed affected customers of the incident via email. The company stated that it detected the intrusion promptly, took the compromised internal system offline, and immediately revoked all active access credentials.
How the Ultrahuman Security Breach Occurred
Malware and Compromised Credentials
Confirming the incident, Ultrahuman told TechCrunch that the attackers gained entry using credentials stolen from an employee’s malware-infected laptop. This unauthorised access allowed the threat actors to view the wellness data of approximately 0.1% of the company’s users.
Based on Ultrahuman’s previously reported figure of roughly 700,000 monthly active users, this percentage equates to at least 700 customers who had their health metrics accessed. While Ultrahuman did not dispute this calculation, the company declined to disclose the exact number of affected customers. The startup emphasised that no passwords, payment information, production systems, or physical Ultrahuman Ring devices were compromised during the incident.
Impact on Customers and Health Data
What Data Was Accessed?
Founded in 2019, Ultrahuman is best known for its Ring Air, a smart ring that monitors sleep, activity, and recovery metrics, competing directly with the Oura Ring. The company also recently introduced the Ring Pro, featuring upgraded sensors and battery life.
In an FAQ published on its website, the startup stated that the threat actor obtained “read-only” access to the affected analytics system. However, Ultrahuman declined to confirm whether its investigation had determined if any customer data was actually exfiltrated from its servers.
The company also declined to share details on whether it had received any communication or ransom demands from the hackers, and did not specify what exactly constitutes “wellness data” within their systems. This breach highlights a persistent risk for users of wellness trackers, as startups like Ultrahuman and Oura store health data on servers in ways that can leave them vulnerable to employees, government requests, and malicious actors.
Company Response and Regulatory Actions
“Our security alerting systems detected the incident within hours, and we closed the vulnerability swiftly,” Ultrahuman CEO Mohit Kumar said in a statement.
Kumar added that the startup is currently notifying relevant regulatory bodies. He explained that the company delayed informing affected users to allow time for a comprehensive audit to determine the full scope of the incident and identify exactly which data points had been accessed.
Investment and Financial Background
Ultrahuman is backed by prominent venture capital firms, including Nexus Venture Partners, Steadview Capital, and Blume Ventures. To date, the startup has raised around $103 million, according to data from market intelligence platform Tracxn.
