23andMe admits it didn’t detect cyberattacks for months
ID: 22e78e83-b49e-5b58-9786-ea36a2a2a7d7
STIX ID: report--22e78e83-b49e-5b58-9786-ea36a2a2a7d7
Feed Name: TechCrunch Security News
Threat Score
Executive summary: 23andMe experienced a prolonged account-compromise incident from April–September 2023 in which attackers brute-forced accounts (exploiting reused/public passwords) to access the DNA Relatives feature and steal ancestry and genetic data for approximately 6.9 million users; the breach was advertised on hacker forums and has prompted class-action lawsuits and public scrutiny of the company’s detection and security practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
