Wearable ring maker Ultrahuman disclosed a security breach exposing customer wellness data after attackers stole credentials from a malware-infected employee laptop. The incident gave hackers access to an internal tool used to manage user information.
Ultrahuman, a biometric wearable company, confirmed that unauthorized parties accessed customer wellness data through an internal company tool. The breach originated from stolen credentials obtained through malware on an employee's laptop.
The company did not specify the exact scope of affected users or the types of wellness data compromised. Ultrahuman's rings track metrics including heart rate, sleep patterns, and activity levels, suggesting these data points may have been exposed.
The attack highlights vulnerabilities in employee cybersecurity practices. Malware infections on company devices remain a common entry point for data breaches, particularly when credentials are not adequately protected through multi-factor authentication or other security controls.
Ultrahuman has not disclosed the full timeline of the breach or when it was discovered. The company typically provides minimal public information about security incidents until required to disclose them.
The incident follows similar breaches at consumer health and fitness companies, where wearable data has become an increasingly attractive target for attackers. Wellness information can reveal personal routines, health conditions, and behavioral patterns valuable to threat actors.
Users of Ultrahuman's rings are advised to monitor their accounts for suspicious activity and consider changing passwords associated with their accounts. The company has not announced a formal notification campaign or compensation plan for affected customers.
This breach underscores the security challenges facing wearable device makers as they collect and store increasingly sensitive biometric information. Companies in the sector face pressure to balance user privacy with the data collection necessary for their products' core functionality.
A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.
The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.
The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.
New research reveals that digital watermarks intended to protect content ownership are being repurposed as surveillance mechanisms to track user behavior and identify individuals across platforms.