Site navigation

23andMe Says Breach Victims Are to Blame, Legal Action is Futile

Michael Edgar

,

23andMe breach
Genetic testing platform 23andMe blames victims of October data breach, a new letter shows. 

Months after the San Francisco based company experienced a data breach impacting about 6.9 million users, 23andMe is now facing criticism for blaming victims of the breach and discouraging legal action. 

The crux of the argument from 23andMe is an interpretation of the California Privacy Rights Act (CPRA) which requires businesses to implement procedures for collecting sensitive data. The law, however, remains vague on what constitutes reasonable security. 

23andMe therefore claims in an open letter that it is not responsible for any security breach, and rather contends that users who “negligently recycled and failed to update their passwords,” after past security incidents bear responsibility.

“We urge you to consider the futility of continuing to pursue an action in this case,” read the letter. 

The exploit was a result of credential stuffing, where threat actors gained access to 14,000 accounts by using emails and passwords lifted from from past data breaches.

From there, they were able to access information from users who opted into the DNA Relatives feature, which allows relatives to access each-other’s information leading to about 6.9 million breached users. 

Despite 23andMe’s assertion that the accessed information posed no threat, lacking information such as social security numbers or financial information, more than 30 lawsuits have been filed against the company.

“Attributing the entirety of blame to users is a flawed argument that oversimplifies the complex landscape of cybersecurity,” said Erfan Shadabi, cybersecurity expert at comforte AG.

According to him, while users do have an obligation to follow best practices for their own safety, companies also have an obligation to protect the sensitive information that has been entrusted to them.

Speaking with TechCrunch, the attorney of over 100 of the victims – Hassan Zavareei – called the company’s response “shameless.”

The class-action lawsuit argues that 23andMe’s security measures were inadequate, and that the company was aware of common user practices and should have implemented safeguards against credential stuffing. 


Recommended reading


The attorney insists that most victims are blameless, having their data exposed through the DNA Relatives feature, not due to recycled passwords.

Zavareei’s firm is seeking damages exceeding $5 million for the loss of personally identifiable information, costs associated with remediating the breach, and emotional distress.

“In this age of sophisticated social engineering attacks, any claim that a data breach can not cause “pecuniary harm” because it did not consist of social security numbers, driver’s license number, or credit card data has to be done tongue in cheek,” said Nick Rago, field CTO at Salt Security.

According to him, these attacks don’t take much information to be effective, and the rise of AI technologies can help threat actors craft social engineering attacks out of information like genealogy or relationship information.  

As the legal battle unfolds, 23andMe faces growing scrutiny and a potentially significant financial burden. The company’s response to the breach continues to draw scrutiny, leaving users seeking accountability and resolution. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data