Breach tracker

Breach report

Ultrahuman says stolen employee credentials exposed some users' wellness data

ConfirmedDisclosed Updated IndiaTechnologyBy Vivek Kumar
Records UnknownCause Data theft
Conceptual illustration: A premium unbranded smart ring beside a phone with abstract fitness curves and anonymous profiles, data fragments escaping from a laptop silhouette. Headline: ULTRAHUMAN DATA EXPOSURE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The wearables maker says an attacker used credentials from a malware-infected employee laptop to get read-only access to an internal analytics system in March. Users heard in June.

What happened

Ultrahuman, the Indian maker of the Ultrahuman Ring, emailed affected customers in early June 2026 to say that an attacker had accessed a system used for internal analytics on 27 March. The company told TechCrunch the attacker used credentials stolen from an employee's laptop that was infected with malware. That is an ordinary infostealer case, not a sophisticated one.

Confirmed vs. claimed

Confirmed by Ultrahuman: the access was read-only and covered contact details, transaction history and some fitness-related data. The company says no passwords, payment or card data were affected, that it took the system offline and revoked access, and that it has informed regulators under data protection law.

Not disclosed: whether data was actually copied out, exactly which wellness metrics were visible, and the number of people affected. The company told TechCrunch about 0.1% of users; with about 7 lakh monthly active users, that is at least 700 people. Customers were told more than two months after the intrusion.

Who is affected

Ultrahuman customers who received the June notification email. No ransom demand or leak listing has been reported.

What to do

  • Check whether you received Ultrahuman's email; if unsure, ask the company through its official app or website.
  • Be wary of messages that mention your ring order, subscription or sleep data and ask you to click, pay or log in.
  • Change your Ultrahuman password if you reuse it anywhere, and turn on two-factor authentication where offered.
  • If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
  • More steps: what to do after a data breach notice.

Sources

More breaches in India