Last updated 2 weeks ago
Telehealth provider Hims & Hers Health experienced a data breach involving unauthorized access to customer support tickets stored on the Zendesk platform. The breach occurred through the compromise of a third-party customer service infrastructure, resulting in the exposure of customer communications and associated personal information. The company confirmed the incident and initiated notification procedures to affected individuals.
The attack chain involved unauthorized access to the Zendesk support ticket system, which serves as a critical customer service interface for the healthcare organization. Attackers exfiltrated support tickets containing customer communications, potentially exposing detailed personal health inquiries, contact information, and service-related discussions. The breach represents a supply chain compromise targeting a widely-used SaaS platform in the healthcare customer service ecosystem.
Hims & Hers has notified affected customers and is working with Zendesk to investigate the incident. The company confirmed the breach through regulatory filings and customer communications, though specific containment timelines and forensic investigation details remain undisclosed. No ransomware payment or regulatory fines have been confirmed at this stage of the incident response.
Support tickets stolen from third-party customer service platform Zendesk
This breach demonstrates the critical risk of third-party SaaS platforms in healthcare, where sensitive patient communications flow through customer service systems not directly controlled by the primary organization. The incident highlights the need for enhanced monitoring of supply chain data flows, particularly for healthcare providers using cloud-based support platforms that handle protected health information. Organizations must implement stricter access controls and data encryption for third-party service integrations, even when those services are considered standard industry tools.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector