Skip to content
NetarxImpact Database
Credential Phishing PortalUnknownConfirmed

Hims & Hers support tickets stolen through compromised Okta SSO accounts

Hims & Hers Health · Healthcare · United States · February 4, 2026

What happened

Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.

How the deception worked

Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.

The control that would have caught it· our reading, not a claim from the sources

Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.

Sources (2)

  1. Hims & Hers warns of data breach after Zendesk support ticket breach
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. Telehealth Giant Hims & Hers Announces Data Breach
    HIPAA Journal·hipaajournal.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.