HomeSecurity23andMe: Blames customer victims for data breach

23andMe: Blames customer victims for data breach

DNA testing company 23andMehas claimed that its customer victims are responsible for a breach data that occurred on its systems a few months ago.

23andMe data breach

23andMe blamed the users whose accounts were compromised for using the same passwords across multiple apps and failing to update their passwords.

The DNA testing company claimed that this allowed the attackers to launch a credential stuffing using usernames and passwords they had access to from other breaches.

See also: HealthEC LLC: Data breach affects 4.5 million patients

23andMe blames the victims and deflects responsibility

23andMe believes that unauthorized actors were able to gain access to certain user accounts because these users reused login credentials — that is, users used the same usernames and passwords on 23andMe.com and other sites that had experienced previous security breaches. Users continued to use the credentials and failed to update their passwords after these previous security incidents, which are unrelated to 23andMe,” said in a letter, which was sent to TechCrunch.

Therefore, the incident was not a result of 23andMe’s alleged failure to maintain reasonable security under the CPRA [California Privacy Rights Act],” 23andMe added.

The data breach took place in October 2023, affecting sensitive information of nearly 7 million customers.

See also: Xerox: Subsidiary XBS US fell victim to ransomware attack and data breach

The hackers initially accessed approximately 14,000 user accounts through the credential stuffing campaign. They then used that information to gain access to the personal data of 6.9 million users who had opted into 23andMe's DNA Relatives feature

In its letter, the company also said that the information the attacker potentially accessed could not have been used to cause “material harm,” as it did not include social security numbers, driver’s license numbers, or any payment information.

23andMe: Backlash against the company

Initially, customers had accused the company of lacking adequate measures to secure user accounts, which led to the breach.

23andMe: Blames customer victims for data breach

Following the incident, 23andMe confirmed that it has added new security measures. This includes terminating all active connected accounts user, requiring password resets on all accounts, and requiring all customers to use two-factor authentication.

Industry experts strongly criticized 23andMe's claim that the victims were to blame for the data breach.

Security expert Erfan Shadabi commented that users do have an obligation to follow best practices in areas like password management, but companies have a duty to protect the sensitive information that customers have entrusted to them.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: EasyPark: Data breach may affect millions of users

Attributing all responsibility to users is a flawed argument that oversimplifies the complex cybersecurity landscape,” he said.

Furthermore, Nick Rago said that 23andMe's argument that the breach cannot cause financial harm because it did not include information such as credit card details is completely unfounded. The stolen information can be used for attacks phishing and theft of other useful information.

Data breach in large companies

Data breaches can have serious consequences for companies, starting with financial loss. This can include both the cost of dealing with the breach and potential legal penalties.

Customer trust can also be seriously undermined . Customers concerned about the security of their personal data may choose not to do business with a company that has been breached.

The reputation may also be damaged, which may affect its ability to attract new customers, investors or partners.

Finally, a data breach can lead to legal repercussions. This can include both sanctions from regulatory agencies and lawsuits from customers affected by the breach, as in the case of 23andMe.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS