23andMe's data hack went unnoticed for months

In late 2023, genetic testing company 23andMe admitted that its customer data was leaked online. A company representative told us back then that the bad actors were able to access the DNA Relatives profile information of roughly 5.5 million customers and the Family Tree profile information of 1.4 million DNA Relative participants. Now, the company has revealed more details about the incident in a legal filing, where it said that the hackers started breaking into customer accounts in late April 2023. The bad actors' activities went on for months and lasted until September 2023 before the company finally found out about the security breach. 

23andMe's filing contains the letters it sent customers who were affected by the incident. In the letters, the company explained that the attackers used a technique called credential stuffing, which entailed using previously compromised login credentials to access customer accounts through its website. The company didn't notice anything wrong until after a user posted a sample of the stolen data on the 23andMe subreddit in October. As TechCrunch notes, hackers had already advertised that stolen data on a hacker forum a few months before that in August, but 23andMe didn't catch wind of that post. The stolen information included customer names, birth dates, ancestry and health-related data. 

23andMe advised affected users to change their passwords after disclosing the data breach. But before sending out letters to customers, the company changed the language in its terms of service that reportedly made it harder for people affected by the incident to join forces and legally go after the company. 

This article originally appeared on Engadget at https://www.engadget.com/23andmes-data-hack-went-unnoticed-for-months-081332978.html?src=rss https://www.engadget.com/23andmes-data-hack-went-unnoticed-for-months-081332978.html?src=rss
Létrehozva 1y | 2024. jan. 26. 10:20:11


Jelentkezéshez jelentkezzen be

EGYÉB POSTS Ebben a csoportban

Perplexity's AI-powered browser opens up to select Windows users

Perplexity is planning to open up its Comet browser that's powered by "agentic search" to Windows users, according to the company's CEO. Aravind Srinivas

2025. jún. 22. 19:40:05 | Engadget
The Blood of Dawnwalker developers share a look at gameplay from the upcoming vampire fantasy RPG

One of the games that really caught my eye during the

2025. jún. 22. 19:40:04 | Engadget
How to buy the Nintendo Switch 2: Latest stock updates at Target, Best Buy, Walmart and more

The Nintendo Switch 2 has been available in the US for more than two weeks — but good luck finding one. While

2025. jún. 22. 17:20:09 | Engadget
Texas will require permits for self-driving cars starting in September

Starting September 1, fully autonomous cars will require a permit to operate in Texas. This new restriction comes after the state's governor, Greg Abbott, signed into law the

2025. jún. 22. 17:20:06 | Engadget
Tesla's inaugural Robotaxi rides will have a human 'safety monitor' on board

A select few will soon get to experience Tesla's robotaxi service for the first time, but they won't be alone in the car. The company plans to launch its fully autonomous ride-hailing service in Au

2025. jún. 21. 18:10:16 | Engadget