The Containment Era is here. →Explore

Executive Summary

In early February 2026, telehealth company Hims & Hers experienced a data breach when unauthorized individuals accessed their third-party customer service platform, Zendesk. The attackers infiltrated the system between February 4 and February 7, compromising support tickets that contained customer names, contact information, and other personal data. Notably, medical records and doctor communications remained unaffected. The breach was attributed to the ShinyHunters extortion group, which exploited compromised Okta SSO accounts to gain access to Zendesk and exfiltrate millions of support tickets. (bleepingcomputer.com)

This incident underscores the escalating threat posed by cybercriminal groups targeting third-party service platforms through sophisticated social engineering and credential compromise techniques. Organizations must enhance their security measures, particularly around SSO systems and third-party integrations, to mitigate such risks.

Why This Matters Now

The Hims & Hers data breach highlights the urgent need for organizations to secure third-party service platforms and SSO systems against sophisticated cyberattacks, as threat actors increasingly exploit these vectors to access sensitive customer data.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach revealed vulnerabilities in third-party service platform security and SSO account management, emphasizing the need for robust access controls and monitoring.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to escalate privileges, move laterally, and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could have limited the attacker's ability to exploit compromised credentials by enforcing strict segmentation and identity-aware policies.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing least-privilege access controls, reducing the scope of accessible resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security could have limited the attacker's ability to move laterally within the environment by enforcing strict segmentation and monitoring internal traffic.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control could have provided real-time monitoring and control over network traffic, potentially identifying and limiting unauthorized data collection activities.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement could have limited the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.

Impact (Mitigations)

While Aviatrix CNSF could have constrained earlier stages of the attack, the impact stage highlights the residual risk where stolen data is used for extortion, emphasizing the importance of comprehensive security measures.

Impact at a Glance

Affected Business Functions

  • Customer Support Services
  • Data Privacy Compliance
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Personal information of customers, including names and contact details, from support tickets.

Recommended Actions

  • Implement phishing-resistant multi-factor authentication (MFA) methods, such as FIDO2 security keys, to mitigate the risk of credential theft.
  • Enhance employee training programs to recognize and respond to social engineering attacks, including voice phishing (vishing) attempts.
  • Deploy Zero Trust Segmentation to enforce least privilege access controls, limiting lateral movement within critical systems.
  • Utilize Threat Detection & Anomaly Response capabilities to identify and respond to unusual access patterns or data exfiltration activities.
  • Regularly review and update access controls and permissions within third-party platforms to ensure they align with the principle of least privilege.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image