news.mlab.sh
Back to the feed
data-breach

California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach

High
Summary

California’s Attorney General has filed a lawsuit against 23andMe, alleging a significant data breach in 2023 that exposed the personal information of nearly 7 million users. The lawsuit highlights 23andMe’s lax security measures, including a failure to implement standard protocols like password resets and multi-factor authentication, and a delayed response to initial warning signs. The incident involved credential stuffing and the sale of stolen data on the dark web, raising concerns about the misuse of sensitive genetic information and exacerbating existing hate crimes.

The lawsuit, filed by Attorney General Rob Bonta, targets Chrome Holding Co., the rebranded entity of 23andMe following its bankruptcy. The breach, occurring in 2023, resulted in approximately 14,000 accounts being accessed, leading to the theft of data including raw genetic information, health reports, and family member details. The attackers exploited ‘credential stuffing,’ leveraging compromised credentials from previous breaches, notably a 2017 MyHeritage incident. 23andMe’s delayed response, only beginning investigation after the data was offered for sale, further compounded the issue. The sale of the data on the dark web, specifically targeting Asian-Pacific Islander and Ashkenazi Jewish users, occurred amidst a backdrop of rising anti-Asian hate and violence, adding a significant layer of concern. The lawsuit also criticizes 23andMe’s misleading communication to consumers regarding the breach’s severity and its failure to investigate earlier red flags, such as suspicious login attempts and a Reddit post discussing a potential breach.

Read the full article at SecurityWeek