California AG sues 23andMe over 2023 breach exposing health data
23andMe faced a significant data breach in 2023, exposing the personal and genetic information of nearly 7 million customers, including a large number in California. The breach stemmed from a credential-stuffing attack and a coding error within the company’s ‘DNA Relatives’ feature, leading to legal action and subsequent financial difficulties. The incident highlighted vulnerabilities in data security practices and prompted investigations by national data protection authorities.
The data breach at 23andMe occurred in October 2023, triggered by an attacker exploiting weak credentials through a credential-stuffing attack. The attackers targeted accounts, particularly those utilizing the ‘DNA Relatives’ feature, and subsequently accessed a larger pool of accounts without this feature. This resulted in the exfiltration of a vast amount of sensitive data, including genetic information, health predisposition details, ancestry data, and DNA matches for approximately 6.9 million customers. The initial response from 23andMe was criticized for downplaying the severity of the breach and shifting blame to customers for password reuse.