
California’s attorney general sued the genetic testing company formerly known as 23andMe for failing to protect sensitive user data after a 2023 breach. The breach affected nearly 7 million people nationwide. The lawsuit seeks civil penalties and injunctions preventing further violations of California privacy protection laws. The company acknowledged a major security incident in 2023 in which about 14,000 accounts were accessed and used to steal data from nearly 7 million customers. The cyberattack used credential stuffing, exploiting weak or reused passwords. The attackers used stolen credentials, including from a 2017 MyHeritage breach. After that breach, 23andMe allegedly did not implement common protections such as password resets or multifactor authentication. The company did not immediately respond to a comment request.
"California's attorney general sued the genetic testing company formerly known as 23andMe on Thursday, alleging it failed to protect sensitive user data in a 2023 breach that affected nearly 7 million people across the country."
"The company has acknowledged that it suffered a major security breach in 2023 that resulted in about 14,000 accounts accessed, through which they were able to steal the data of nearly 7 million customers. The cyberattack utilized "credential stuffing," which takes advantage of customers' tendency to use weak or common passwords or reuse passwords between multiple accounts."
"The attackers used stolen user account credentials including ones from a massive data breach in October 2017 that affected MyHeritage, one of 23andMe's former partners. After that breach, 23andMe did not take common protocols such as asking customers to reset their passwords or use multifactor authentication."
""23andMe's security measures were so lax that the threat actor was able to operate undetected within 23andMe's systems for over five months, and remarkably, 23andMe only began investigating after the threat actor offered the stolen user data for sale on the dark web and reach"
#california-privacy-law #data-breach #genetic-testing #credential-stuffing #cybersecurity-enforcement
Read at ABC7 San Francisco
Unable to calculate read time
Collection
[
|
...
]