Complete Story
 

01/07/2024

23andMe Blames Users for Recent Data Breach

The company has been hit with dozens of lawsuits

At the beginning of October, 23andMe said that attackers had infiltrated some of its users' accounts and abused this access to scrape personal data from a larger subset of users through the company's opt-in social sharing service known as DNA Relatives. By December, the company disclosed that the number of compromised accounts was roughly 14,000 and admitted that personal data from 6.9 million DNA Relatives users had been impacted.

Now, facing more than 30 lawsuits over the breach—even after tweaking its terms of service to make legal claims against the company more difficult—the company said in a letter to some individuals that “users negligently recycled and failed to update their passwords following... past security incidents, which are unrelated to 23andMe.”

This references 23andMe’s long-standing assessment that attackers compromised the 14,000 user accounts through "credential stuffing," the process of accessing accounts using usernames and passwords compromised in other data breaches from other services that people have reused on multiple digital accounts. "Therefore, the incident was not a result of 23andMe's alleged failure to maintain reasonable security measures," the company wrote in the letter.

Please select this link to read the complete article from WIRED.

Printer-Friendly Version