news.mlab.sh
Back to the feed
data-breach

Sanction de 23andMe après une fuite de données

High
Image: ZATAZ
Summary

23andMe has been fined 2.4 million euros by the Spanish data protection regulator (AEPD) for a data breach in 2023 that impacted 6.9 million people globally, including over 2,600 Spanish residents. The regulator cited several shortcomings in 23andMe's security practices, including a lack of multi-factor authentication, insufficient access controls, and a delayed notification to authorities. The incident was triggered when a user attempted to sell a sample of the stolen data on Reddit. Furthermore, 23andMe reached a separate settlement with US prosecutors for $18 million. The case highlights the importance of aligning security controls with the sensitivity of protected data, even when risks are identified.

Read the full article at ZATAZ

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.