Wearable ring maker Ultrahuman disclosed a security breach exposing customer wellness data after attackers stole credentials from a malware-infected employee laptop. The incident gave hackers access to an internal tool used to manage user information.
Ultrahuman, a biometric wearable company, confirmed that unauthorized parties accessed customer wellness data through an internal company tool. The breach originated from stolen credentials obtained through malware on an employee's laptop.
The company did not specify the exact scope of affected users or the types of wellness data compromised. Ultrahuman's rings track metrics including heart rate, sleep patterns, and activity levels, suggesting these data points may have been exposed.
The attack highlights vulnerabilities in employee cybersecurity practices. Malware infections on company devices remain a common entry point for data breaches, particularly when credentials are not adequately protected through multi-factor authentication or other security controls.
Ultrahuman has not disclosed the full timeline of the breach or when it was discovered. The company typically provides minimal public information about security incidents until required to disclose them.
The incident follows similar breaches at consumer health and fitness companies, where wearable data has become an increasingly attractive target for attackers. Wellness information can reveal personal routines, health conditions, and behavioral patterns valuable to threat actors.
Users of Ultrahuman's rings are advised to monitor their accounts for suspicious activity and consider changing passwords associated with their accounts. The company has not announced a formal notification campaign or compensation plan for affected customers.
This breach underscores the security challenges facing wearable device makers as they collect and store increasingly sensitive biometric information. Companies in the sector face pressure to balance user privacy with the data collection necessary for their products' core functionality.
Hackers claim to have compromised the Federal Bureau of Investigation and obtained personal data on all FBI employees. The breach's scope and authenticity have not yet been independently verified.
Researchers at Cisco Talos developed a new framework to detect malware and hacking tools powered by AI chatbots. The discovery revealed an unusual threat: autonomous malware operating without human handlers.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive ordering federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches. Attackers are actively exploiting the flaw to steal data.
WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.