In early April 2026, Hims & Hers, a prominent telehealth company specializing in weight-loss drugs and sexual health prescriptions, disclosed a significant data breach. The breach occurred between February 4 and 7, 2026, when hackers infiltrated a third-party customer service platform used by the company. This unauthorized access compromised support tickets containing personal information submitted by customers. The compromised data included customer names, contact information, and other unspecified personal details. Notably, Hims & Hers stated that medical records were not affected by the breach. However, the nature of the customer support system means that the stolen data could contain sensitive information about individuals' accounts and healthcare. The company attributed the breach to a social engineering attack, where hackers deceived employees into granting access to their systems. This method underscores the growing sophistication of cyberattacks targeting customer support and ticketing systems, which have become lucrative targets for cybercriminals seeking valuable personal data. As of now, the exact number of affected individuals remains unknown. Under California law, companies are required to disclose data breaches involving 500 or more state residents. Hims & Hers is currently investigating the full extent of the breach and working to notify affected customers. This incident highlights the critical importance of robust cybersecurity measures, especially for companies handling sensitive personal and health information. It also raises questions about the security practices of third-party vendors and the need for comprehensive security protocols to protect customer data.