Ultrahuman Data Breach: Hackers Accessed User Health Info
Ultrahuman, the India-based wearable health technology startup, has disclosed a security breach that exposed sensitive customer wellness data. The incident, which took place on March 27, stemmed from a compromised employee account targeted by malware.

The company confirmed that attackers utilized stolen credentials from a malware-infected laptop to gain entry to an internal analytics system. While the startup has not provided an exact count of impacted individuals, it noted that roughly 0.1% of its user base was affected. Given the company’s reported 700,000 monthly active users, this suggests at least 700 customers had their information exposed.
Incident Response and Data Impact
According to Ultrahuman CEO Mohit Kumar, the company’s internal security systems identified the intrusion within hours. The firm subsequently took the affected system offline and revoked all unauthorized access to mitigate further risk.
The startup clarified that the breach did not compromise critical user assets. The following information remained secure during the incident:
- User passwords
- Payment information
- Production systems
- Hardware functionality (Ultrahuman Ring devices)
In an official FAQ published on its website, the company stated that the unauthorized actors obtained “read-only” access to the internal tool. However, Ultrahuman has not yet confirmed whether any specific customer data was successfully exfiltrated during the breach.
Addressing Security Concerns
The company, which produces health-tracking hardware such as the Ring Air and the recently released Ring Pro, began notifying impacted users via email this Wednesday. CEO Mohit Kumar noted that the delay in notification was intentional, allowing the security team time to audit the incident and determine the full extent of the data exposure.
Ultrahuman, which has raised around $103 million from investors including Nexus Venture Partners, Steadview Capital, and Blume Ventures, is currently coordinating with regulators. The startup declined to comment on whether the hackers had made any direct communication or to specify exactly what information is categorized as “wellness data” within its analytics platform.
The incident underscores the growing security risks faced by health tech companies like Ultrahuman and Oura, as they store vast amounts of biometric data that remain vulnerable to both internal access and external cyberattacks.