Skip to content
Notice March 2026

Notice March 2026

www.ultrahuman.com June 5, 2026

This page is a public record of a security incident that affected Ultrahuman's systems on 27 March 2026. The most important facts first: no passwords, card details, or payment data were involved, and we have found no evidence of misuse.

If you received an email from [email protected] referencing this incident, your account was part of the affected dataset. The email lists the specific categories of information involved for your account. This page exists to give you a clear public summary of the incident.

On 27 March 2026, an unauthorised third-party gained read-only access to an internal system used for internal analytics. The access was constrained in scope by the system's design, which did not permit modification or deletion of data. We identified the incident promptly, took the affected system offline, and revoked all access.

The information visible to the unauthorised individual varied by account. The dataset that was accessed contained, depending on the user, and account details, order and transaction history, and for a smaller group of users, some fitness related data associated with their product usage and purchases.

No passwords, payment or credit card information were accessible or affected by this incident. The Ultrahuman Ring continues to operate normally and to record accurate wellness information.

After identifying the incident, we immediately took the affected system offline and revoked all access. We have since implemented the following remediation measures:

We have also conducted active monitoring of public and other internet channels for any evidence of the publication or further misuse of the accessed information. To date, we have not identified any such publication or misuse.

Affected users. All affected users have been notified directly by email on or after 2 June 2026. The email was sent from [email protected] with the subject line "A security notice from Ultrahuman your account." Each email specifies the categories of information visible for the recipient's account.

If you believe you may be affected but have not received an email, please write to [email protected] for confirmation.

Regulatory authorities. Ultrahuman has notified the relevant regulatory authorities under applicable data protection law.

As a precaution, and as is standard practice after any incident, be alert to phishing attempts. If you receive any unexpected email, SMS, or telephone call referencing Ultrahuman, your orders, or your personal data, please treat it with caution, particularly where it conveys urgency or requests that you click a link.

Ultrahuman will not ask you to confirm your password, payment details, or any other personal information by email or SMS.

For questions, Write to [email protected] and someone from the Ultrahuman team will respond. We take this incident seriously. The measures we have taken are designed to prevent a recurrence, and we remain committed to earning your trust every day.

Frequently asked questions the security incident at Ultrahuman in March 2026. If your question isn't answered below, write to [email protected] and someone from the Ultrahuman team will respond.

On 27 March 2026, an unauthorised third party gained access to an internal analytics system. We disabled the access, secured the tool, and have since investigated to determine exactly what information was visible for each affected person. We have now contacted everyone whose data was in the affected dataset.

If you received an email from [email protected] with subject line "A security notice from Ultrahuman your account" on or after 2 June 2026 this incident, your account was part of the affected dataset. The email tells you what was visible for your account. If you have an Ultrahuman account but have not received an email, your account was not in the affected dataset. If you are unsure, write to security-2026@ultrahuman.com and we will get back.

This varies by account. The dataset that was accessed contained the kind of information you provided when signing up and using Ultrahuman — such as details and order or transaction history. For a smaller group of users, the dataset also contained fitness-related data. Your specific notification email lists the categories applicable to your account.

No immediate action is required. Your account, your Ultrahuman app, and your Ring all continue to work as normal.

As a precaution, and as is standard practice after any incident, be alert to phishing attempts. Treat any unexpected email, SMS, or call that references Ultrahuman, your orders, or your personal information with extra caution — especially anything urgent or asking you to click a link, log in, or information. We will never ask you to confirm a password, payment details, or health information by email or SMS. If you receive something suspicious that appears to be from us, forward it to [email protected] .

No. Ultrahuman uses Google, Apple, or sign-in only, so there is no Ultrahuman password to change. Your sign-in provider's account itself was not breached. As good security hygiene, we recommend reviewing the security settings on your sign-in provider — including enabling two-step verification if you have not already.

Yes — absolutely. Your Ultrahuman app, your Ring, and the systems that power your day-to-day experience were not affected by this incident. This incident was confined to an internal analytics tool and it never touched the platforms you interact with.

As of today, we have not seen any of the data published or offered for sale, and we are actively monitoring for it. If that changes, we will you directly.

Here is the work we have done, and continue to do, so that this specific failure mode is no longer possible:

Any future communication this incident will come from an Ultrahuman email via the email address you registered with us. We will never ask you to click links to verify your account, confirm passwords, or payment information by email. If you receive a message claiming to be from us and you are unsure, forward it to [email protected] and we will confirm.

Yes. We have notified the relevant regulatory authorities under applicable data protection laws.

Write to [email protected] and someone from the Ultrahuman team will respond.

Extracted Entities

Attack Types (1)

Companies (1)