bleeping-computer · Crawled Jul 16, 2026

23andMe to pay $18 million in new genetics data breach settlement

Read original article ↗

AI Summary

23andMe suffered a significant data breach in 2023 due to credential-stuffing attacks that went undetected for five months, resulting in the theft of genetic and personal data from 6.9 million customers. The breach was attributed to inadequate security controls, including lack of password blocklisting, multifactor authentication, and intrusion detection. The company faced multiple lawsuits, regulatory fines, and ultimately a bankruptcy filing, culminating in a $18 million settlement with a coalition of 43 attorneys general to resolve claims over its failure to protect user data.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.