
Indian health and wellness technology company Ultrahuman said it suffered unauthorised access to an internal system that exposed customers’ contact information and health data.
The Bengaluru-headquartered company announced in a security incident notification that the data breach occurred on March 27, 2026, when an unauthorised third party used malware to steal an employee’s login credentials and used them to access the internal system used for internal analytics.
"The information visible to the unauthorised individual varied by account. The dataset that was accessed contained, depending on the user, contact and account details, order and transaction history, and for a smaller group of users, some fitness related data associated with their product usage and purchases," Ultrahuman said.
"No passwords, payment or credit card information were accessible or affected by this incident. The Ultrahuman Ring continues to operate normally and to record accurate wellness information," it added, stating that the accessed information was read-only and could not be modified or deleted.
Ultrahuman has a customer base of over 700,000 people and sells sleep-tracking, glucose monitoring, blood testing and health mapping devices and integrates data from different devices to give customers a clear picture of their health status. The company’s wellness products give users information about their lifestyle, environment markers that affect their health, and their exposure to artificial light, air quality, humidity, and noise levels.
The company said that as soon as it detected the unauthorised access, it took the affected system offline and quickly revoked the third party’s access. It also strengthened access control policies across internal systems, hardened endpoint security on all employee devices, increased the frequency of periodic access audits across internal tooling, and deployed export-volume anomaly detection and alerting on internal systems.
"We have also conducted active monitoring of public and other internet channels for any evidence of the publication or further misuse of the accessed information. To date, we have not identified any such publication or misuse," it added.
The company’s CEO Mohit Kumar told TechCrunch that the security incident was detected within hours, but Ultrahuman delayed its notifications to affected users as it wanted to complete its investigation into the incident to understand its full scope and determine what data had been affected. He also told the publication that the incident affected approximately 0.1% of the company’s global user base.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543