Ultrahuman Data Leak, Ransomware Tradecraft, and a Browser That Mines Your CPU: The Week's Overlooked Stories
Three stories that didn't dominate the feed — a wearable-tech data exposure, a dissection of The Gentlemen ransomware, and Hola Browser quietly bundling a cryptominer.

Some weeks the headline stories vacuum up all the oxygen. Here's what got left behind.
Ultrahuman data leak
Ultrahuman, the Finnish-American maker of the Ring AIR biometric wearable, exposed user data. The company has not published a formal incident notice specifying PII categories, record counts, or the date range of affected records — which is itself a story. Wearable devices collect unusually sensitive biometric signals: resting heart rate, skin temperature, sleep-stage data, activity patterns. Depending on where affected users are located, notification obligations fall to the FTC under the Health Breach Notification Rule, the ICO under UK GDPR, or various EU supervisory authorities. None have issued public statements as of writing. Ultrahuman has not responded to requests for specifics.
The Gentlemen ransomware, dissected
Researchers published an analysis of The Gentlemen ransomware — a strain that appears to prioritise operational security and clean extortion mechanics over high victim volume. The tradecraft is notable: deliberate lateral movement, selective encryption to avoid triggering volume-based detection, and ransom notes tailored per target. Nothing about this is exotic. What it is, is patient. That patience is the actual threat model most detection tools still underweight.
Hola Browser bundles a cryptominer
Hola Browser — already carrying a troubled history around selling user bandwidth through its VPN product — shipped builds that bundled a cryptominer. Users who installed the browser were contributing CPU cycles to someone else's mining operation. The vector is blunt: a consumer-facing installer. No exploit required. The relevant regulator for UK users is the ICO; for US users, the FTC's Section 5 unfair-practices authority is the obvious hook. Hola has not issued a public explanation of how the miner entered the build pipeline or which versions were affected.
What affected users should do
Ultrahuman Ring AIR owners: audit what health data the app holds, check whether account-export features reveal unexpected third-party sharing, and monitor for phishing using health-related pretexts. Hola Browser users: uninstall immediately, run a full antivirus scan, and check CPU usage logs for unexplained spikes during the period the browser was installed. Check your browser extension list — Hola's extension and standalone browser are separate products with overlapping risks.


