Glucobit Inc. dba Reframe, a health-technology company, experienced a cybersecurity incident that was disclosed in 2026. The company reportedly discovered the breach by May 1, 2026, and began notifying affected individuals by June 30, 2026. This incident was confirmed through regulatory filings with the California Attorney General and was also referenced in a Texas regulatory listing. The breach did not involve a third-party vendor.
Public descriptions indicate that names and health records or medical information may have been compromised. Glucobit stated that it does not collect Social Security numbers, driver’s license numbers, or payment card or bank information, and these data types were not involved. The incident affected an estimated 43,902 individuals.
Further details about the incident may emerge over time as investigations continue. Consumer notices were reportedly sent starting in late June 2026.