logo

Infosec experts divided over 23andMe's 'victim-blaming' stance on data breach

ID: 68e848db-d856-5654-a339-cabacf80f99c

STIX ID: report--68e848db-d856-5654-a339-cabacf80f99c

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-01-04

Date Updated: 2026-04-26

Author: Connor Jones

...
...

23andMe suffered a credential-stuffing-driven breach in October that resulted in roughly 14,000 account takeovers and the compromise of data belonging to about 6.9 million users; the company and its legal team attributed the incident largely to users reusing breached credentials while critics pointed to the absence of mandatory MFA and compromised-credential checks as major failures and recommended integrations (e.g., HaveIBeenPwned) and default MFA to mitigate such attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.