{"id":23627,"date":"2024-01-13T12:25:27","date_gmt":"2024-01-13T20:25:27","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/01\/13\/news-17357\/"},"modified":"2024-01-13T12:25:27","modified_gmt":"2024-01-13T20:25:27","slug":"news-17357","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/01\/13\/news-17357\/","title":{"rendered":"23andMe blames &#8220;negligent&#8221; breach victims, says it\u2019s their own fault"},"content":{"rendered":"\n<p>In a surprising move, in a <a href=\"https:\/\/www.documentcloud.org\/documents\/24252535-response-letter-to-tycko-zavareei-llp\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">letter to legal representatives of victims<\/a> of the recent <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/10\/23andme\">23andMe data breach<\/a>, the company has laid the blame at the feet of victims themselves.<\/p>\n<p>23andMe even goes as far as to claim that this wasn\u2019t a data breach at 23andMe at all. The reasoning:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\u201c&#8230; unauthorized actors managed to access certain user accounts in instances where users recycled their own login credentials\u2014that is, users used the same usernames and passwords used on 23andMe.com as on other websites that had been subject to prior security breaches, and users negligently recycled and failed to update their passwords following these past security incidents, which are unrelated to 23andMe.\u201d<\/p>\n<\/blockquote>\n<p>In other words, it was their own fault since they re-used their passwords for services that were breached in the past. Accessing accounts on a website by using lists of usernames and passwords exposed on another is known as \u201ccredential stuffing\u201d, and it\u2019s both common and effective. It works because users often use the same password for multiple websites.<\/p>\n<p>What 23andMe seems to have forgotten is that only 14,000 accounts were breached by credential stuffing. Afterwards, the attackers used those accounts to access a much larger trove of data via 23andMe&#8217;s feature called DNA Relatives which matches users with their genetic relatives.<\/p>\n<p>So, in what was only made possible by 23andMe, customers who didn\u2019t re-use their passwords and even had <a href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\">2FA<\/a> enabled still saw their data stolen. This resulted in the data of as many as seven million 23andMe customers being offered for sale on criminal forums. <\/p>\n<p>We spoke about the breach in our most recent Lock and Code podcast episode. You can listen to that wherever you get your podcasts, or below:<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-spotify wp-block-embed-spotify wp-embed-aspect-21-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\"> https:\/\/open.spotify.com\/episode\/4ubXicnijYEyCEAAngDY1F?go=1&#038;sp_cid=badd369a49adcfc92e556cb4bdebcb6d&#038;utm_source=embed_player_p&#038;utm_medium=desktop <\/div>\n<\/figure>\n<p>This is the second time the company has attempted to downplay the incident. In its first communication about the incident, 23andMe claimed the stolen data did not include genomic sequencing data.\u00a0 Later, the company acknowledged that for a subset of these accounts, the stolen data might indeed contain health-related information based upon the user\u2019s genetics.<\/p>\n<p>The data in a file found by <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/23andme-hit-with-lawsuits-after-hacker-leaks-stolen-genetics-data\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BleepingComputer<\/a> contained information including 23andMe users&#8217; account IDs, full names, sex, date of birth, DNA profiles, location, and region details.<\/p>\n<p>As a result, at least four class action complaints were submitted in California seeking relief for the damage done by 23andMe&#8217;s failure to protect customer data. The lawsuits focus on different failures on 23andMe\u2019s side to guard the safety of sensitive data, communicate appropriately about the incident, and monitor its network for abnormal activity.<\/p>\n<p>In its defense, 23andMe reasons that customers re-used their passwords, gave permission to share data with <strong>other users<\/strong> on 23andMe\u2019s platform, and that the medical information was non-substantive.<\/p>\n<p>I put the emphasis on &#8220;other users&#8221; in order to point out a flaw in 23andMe\u2019s reasoning\u2014agreeing to share with other users is hardly the same as agreeing to share with a data thief. Without knowing the exact details of what happened, we feel that monitoring would indeed have raised alerts about abnormal activity and allowed them to stop the breach earlier. As it seems now, 23andMe only became aware of a problem when someone offered the data up for sale.<\/p>\n<p>Whatever the judges may decide in the end, it&#8217;s looking like 23andMe has shown a lot of disregard for its customers&#8217; privacy and the level of sensitivity of the data.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-data-breach\">Data breach<\/h3>\n<p>There are some actions you can take if you are, or suspect you may have been, the&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/blog\/personal\/2023\/09\/involved-in-a-data-breach-heres-what-you-need-to-know\">victim of a data breach<\/a>.<\/p>\n<ul>\n<li><strong>Check the vendor\u2019s advice.<\/strong>&nbsp;Every breach is different, so check with the vendor to find out what\u2019s happened, and follow any specific advice they offer.<\/li>\n<li><strong>Change your password.<\/strong>&nbsp;You can make a stolen password useless to thieves by changing it. Choose a&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/computer\/how-to-create-a-strong-password\" target=\"_blank\" rel=\"noreferrer noopener\">strong password<\/a>&nbsp;that you don\u2019t use for anything else. Better yet, let a&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/what-is-password-manager\" target=\"_blank\" rel=\"noreferrer noopener\">password manager<\/a>&nbsp;choose one for you.<\/li>\n<li><strong>Enable two-factor authentication (2FA).<\/strong>&nbsp;If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\" target=\"_blank\" rel=\"noreferrer noopener\">two-factor authentication (2FA)<\/a>&nbsp;can be phished just as easily as a password. 2FA that relies on a FIDO2 device can\u2019t be phished.<\/li>\n<li><strong>Watch out for fake vendors.<\/strong>&nbsp;The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify any contacts using a different communication channel.<\/li>\n<li><strong>Take your time.<\/strong>&nbsp;Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.<\/li>\n<li><strong>Set up identity monitoring.<\/strong><a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">Identity monitoring<\/a>&nbsp;alerts you if your personal information is found being traded illegally online, and helps you recover after.<\/li>\n<li><\/li>\n<\/ul>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using\u00a0<a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes Identity Theft Protection<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/01\/23andme-blames-negligent-breach-victims-says-its-their-own-fault\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> 23andMe has responded in a letter to legal representatives of data breach victims that they were to blame themselves for re-using passwords <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[20260,11172,32,30647],"class_list":["post-23627","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-23andme","tag-data-breach","tag-news","tag-re-used-passwords"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23627","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23627"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23627\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}