Ultrahuman says its security systems flagged and closed an intrusion within hours, yet attackers still accessed wellness records for about 0.1 percent of users. The India-based wearable startup told affected customers this week that intruders used credentials stolen from a malware-infected employee laptop to reach an internal analytics tool on March 27. Ultrahuman notified those users by email on June 3, and CEO Mohit Kumar told TechCrunch the company moved quickly to take the impacted system offline and revoke access. The firm says passwords, payment information, production systems and its Ring devices were not compromised while an audit and regulator notifications continue.
Ultrahuman says it shut the door fast, but the intruders had already walked through a side window on March 27. That's the company’s account of how attackers used credentials taken from a malware-infected employee laptop to log into an internal analytics system and view wellness records for a small slice of its user base.
The startup, founded in 2019 and known for the Ring Air and the recently introduced Ring Pro, told affected users this week that the intrusion was detected and contained within hours. Ultrahuman said it took the analytics system offline, revoked the compromised credentials and emailed impacted customers on June 3. In a statement to TechCrunch, CEO Mohit Kumar said, "Our security alerting systems detected the incident within hours, and we closed the vulnerability swiftly."
What the company says was exposed
Ultrahuman has characterised the attackers' access as "read-only" in a public FAQ, saying the intruders accessed an internal analytics tool rather than production systems. The company also stated that no passwords, payment information, production systems, or Ring devices were compromised.
Still, Ultrahuman declined to specify which exact fields it meant by "wellness data" and wouldn't confirm whether investigators had found evidence that any data was copied out of its systems. The firm said it delayed public notification while it audited the full scope of the incident, and it confirmed it's notifying regulators without naming which authorities have been contacted.
Ultrahuman told reporters the breach affected about 0.1 percent of users.
Using the company’s previously stated figure of roughly 700,000 monthly active users, that proportion translates to at least 700 individual customers, a calculation the company didn't dispute while it withheld an exact headcount.
The startup sells smart rings and metabolic trackers that report metrics such as sleep, activity and recovery. Its Ring Air competes with the Oura Ring, and the firm recently rolled out the Ring Pro with upgraded sensors and battery life. Ultrahuman counts Nexus Venture Partners, Steadview Capital and Blume Ventures among its backers, and it has raised about US$103 million to date, according to Tracxn.
Credential theft through malware on employee devices is a common pattern in breaches. Ultrahuman said the attackers used credentials stolen from an infected laptop to reach the analytics system. The company’s immediate containment steps were straightforward: disable the impacted system, revoke credentials, and communicate with affected users.
But the incident highlights a structural risk in many modern product teams. Centralised analytics platforms collect dense biometric and behavioural signals that are useful to product and research teams. Those same platforms make sensitive data accessible to employees, and if an employee credential is compromised, an outsider can inherit that access.
Ultrahuman framed the risk as limited by the exclusions it listed. It emphasised that core systems and device security were not breached and that payment credentials remain safe. Yet the lack of a precise definition for "wellness data" and the company’s refusal to confirm or deny data exfiltration leave key questions open for users and regulators.
The company also wouldn't say whether it had received any ransom demands or other communication from the threat actor. That silence follows a common practice where firms either don't disclose ransom talks or avoid confirming extortion to limit buyer incentives for attackers.
Ultrahuman’s public disclosures on June 3 remain its most concrete actions so far: taking the analytics system offline, revoking access, emailing affected customers and posting the FAQ describing the incident as read-only. The audit is ongoing and the company hasn't provided a final count of impacted accounts.
For users, the immediate practical reassurance is narrow but specific. Ultrahuman says no credentials or payment details were leaked, and no Ring devices or production systems were touched. For product teams and security professionals, the episode is a reminder that endpoint hygiene and multi-factor protections around analytics tools are critical, because those systems can concentrate highly sensitive signals in a single place.
Related Articles
- Cyberdecks surge as DIY privacy and thrift culture grow
- 90% savings, 15s risk: build interrupt‑resilient AI on GKE
- How a router-level VPN protects smart TVs and your home network
An internal audit is ongoing and regulators have been notified; Ultrahuman has not published a final headcount or confirmed whether any data was copied out of its systems. Originally reported by TechCrunch.
This article was created with AI assistance.