23andMe to pay $30 million in genetics data breach settlement
ID: ea38837f-dfc7-5a5c-8d2f-c72af578a824
STIX ID: report--ea38837f-dfc7-5a5c-8d2f-c72af578a824
Feed Name: Bleeping Computer
23andMe experienced a credential-stuffing breach in 2023 that resulted in the theft and public leaking of sensitive data — including health reports and raw genotype files — for roughly 6.9 million customers (about 6.4 million U.S. residents). The incident led to multiple class-action lawsuits and a proposed $30 million settlement; 23andMe denies wrongdoing but agreed to strengthen security controls (mandatory 2FA, protections against credential stuffing, annual audits, incident response planning, and data-retention limits).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
