Infosec experts divided over 23andMe's 'victim-blaming' stance on data breach
ID: 68e848db-d856-5654-a339-cabacf80f99c
STIX ID: report--68e848db-d856-5654-a339-cabacf80f99c
Feed Name: The Register (Security)
23andMe suffered a credential-stuffing-driven breach in October that resulted in roughly 14,000 account takeovers and the compromise of data belonging to about 6.9 million users; the company and its legal team attributed the incident largely to users reusing breached credentials while critics pointed to the absence of mandatory MFA and compromised-credential checks as major failures and recommended integrations (e.g., HaveIBeenPwned) and default MFA to mitigate such attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
