In a letter to a group of victims of its October 2023 breach, 23andMe blames them, saying that “users negligently recycled and failed to update their passwords”
Facing more than 30 lawsuits from victims of its massive data breach, 23andMe is now deflecting the blame …
TechCrunch Lorenzo Franceschi-Bicchierai
Related Coverage
- 23andMe blames users recycling passwords for data breach Silicon Republic · Leigh Mc Gowran
- 23andMe: It's YOUR Fault We Lost Your Data Security Boulevard · Richi Jennings
- 23andMe blames security breach on users who “negligently” recycled passwords. The Verge · Emma Roth
- 23AndMe: The Genetics of Finger Pointing Beyond Search · Stephen E. Arnold
- 23andMe says it's your fault if you're among 6.9 million of its users affected by recent data breach MSPoweruser · Rafly Gilang
- 23andMe blames users for data breach, citing recycled passwords New York Post · Eric Revell
- 23andMe to Data Breach Victims: It's Your Fault! Gizmodo · Lucas Ropek
- 23andMe blames users for security breach, says they should have been better at passwords TechRadar
- DNA Testing Company 23andMe Blames Its Users for Data Breach The Messenger · Claire Cameron
- Letters Dated November 9 and November 22 Greenberg Traurig, LLP
- Just deleted my 23andMe account. A little late perhaps, but before the next hack, although I still haven't gotten any confirmation if I was one of the people hacked. I did find my birth family through them, so that was sorta positive, but there's no need to stay on at this point. … @ukuku@mstdn.social · James
- The nerve of these assholes — https://techcrunch.com/... @jalefkowit@octodon.social · Jason Lefkowitz
- 23AndMe blaming users for a data breach that impacted 6.9M people because 14,000 of them used previously hacked passwords is poor. — Apps have many options to prevent this including 2-factor auth & using the Have I Been Pwned API. This is victim blaming. — https://techcrunch.com/... @carnage4life@mas.to · Dare Obasanjo
- “From these 14,000 initial victims, however, the hackers were able to then access the personal data of the other 6.9 million million victims because they had opted-in to 23andMe's DNA Relatives feature.” https://techcrunch.com/... someone who knows graph modeling that can visualize that? … @mgiraldo@mstdn.social
- 23andMe tells victims it's their fault that their data was breached Hacker News
Discussion
-
@georgebetak
George Betak
on threads
Thank you! I reviewed the emails I've received from @23andme to see how it aligns with the @techcrunch article. I couldn't help noticing this email from December 1, 2023. This doesn't sit well with me. I haven't seen that email and had no opportunity to evaluate any changes t…
-
@ciprimusic
Cipri
on threads
I just got an email from 23andme stating my data was stolen from a DNA test I took in 2013. Apparently the data breach only affected a small number of people but seriously wtf. This is why I have trust issues! How reassuring. Hopefully I'm not cloned. 😠🙄🙄🙄
-
@tyler.l.rhodes
Tyler Rhodes
on threads
At least 23AndMe didn't say the hack was due to genetics
-
@awakentheraven
@awakentheraven
on threads
23andMe admitted that hackers had stolen the genetic and ancestry data of 6.9 million users. Now in a letter sent to a group of hundreds of 23andMe users who are suing the company, 23andMe said that “users negligently recycled and failed to update their passwords following these…
-
@dangillmor@mastodon.social
Dan Gillmor
on mastodon
23andMe's security failure is — you guessed it — the users' fault, the slimy company insists. — It's the latest tech industry effort to escape responsibility for its own routine indifference to people's privacy. …
-
@counternotions@mastodon.social
@counternotions@mastodon.social
on mastodon
Best corporate job in 2024? — Data/Privacy Lawyer, especially at 23andMe. — https://techcrunch.com/...
-
@justcodeculture.bsky.social
Jeffrey Yost
on bluesky
On top of a major data breach that compromised genetic info. of half of its past customers in their database, over 6.9 million ppl, 23andme is now unconscionably compounding its wrongdoings by blaming victims! #histsci #privacy — techcrunch.com/2024/01/03/2...
-
@alexanderchopan.bsky.social
@alexanderchopan.bsky.social
on bluesky
https://techcrunch.com/... “In other words, by hacking into only 14,000 customers' accounts, the hackers subsequently scraped personal data of another 6.9 million customers whose accounts were not directly hacked.”
-
@thomasfuchs.at
Thomas Fuchs
on bluesky
The 23andMe saga continues, this time they're... ...checks notes... ...blaming victims for having their account data and DNA stolen. — I bet the company leadership is fun at parties.
-
@gregpoirier.bsky.social
Greg
on bluesky
Reminder on the context “In December, 23andMe admitted that hackers had stolen the genetic and ancestry data of 6.9 million users, nearly half of all its customers.” [embedded post]
-
@drakenblackknight.bsky.social
@drakenblackknight.bsky.social
on bluesky
Well...I mean, technically 23andMe is right. It was the customers' own fault they were breached. No one in their right mind should be using their “service” because it says in their fucking ToS that they own your DNA once you submit it.
-
@racheltobac
Rachel Tobac
on x
I would love to see orgs take ownership of the behavior allowed on their site — rather than blaming users for poor passwords, one great option for orgs is to integrate Haveibeenpwned to alert users if their password has been compromised and shouldn't/can't be used on the site....
-
@twilight2000
@twilight2000
on x
https://techcrunch.com/... even if the first 14,000 were using the same password for every single account they owned and you want to blame them the other 6.9 million who were hacked because they turned on your optional tool are clearly your fault.
-
@erratarob
Robᵉʳᵗ Graham
on x
But @23andme is right, it's the customer's fault that they got hacked. It's something the customer did, not something @23andme did. If you deliberately drive into a tree with your Toyota, it's not Toyota's fault you crashed your car.
-
@lordguthrie
Shaun Guthrie
on x
Wow @23andMe , victim blaming. Not a great look. Maybe your PR team needs a lesson. How about you take responsibility and do the right thing. https://techcrunch.com/...
-
@jsrailton
John Scott-Railton
on x
I'm cynical about how most companies handle cybersecurity incidents. But I'm left staring in puzzled wonderment at @23andMe finding a way to victim-blame their users for a massive breach. By @lorenzofb h/t @RachelTobac https://techcrunch.com/... [image]
-
@geek_news
@geek_news
on x
Now here a new one, blame your users for their data being stolen off your databases SMFH. People wonder why I always say #PrivacyMatters and no company should have too much information and data on their customers/users! https://techcrunch.com/... via @techcrunch
-
@presentservices
@presentservices
on x
I know it's too late for many people and we've long since lost the privacy wars but please don't do these tests for some corporate company that will just sell (or lose) your info than blame you for the loss. https://techcrunch.com/...
-
@_garethwilliams
@_garethwilliams
on x
Just when you thought things couldn't get much worse for 23andMe... 🤦 This could easily become a case study in how not to handle a data breach! https://techcrunch.com/...
-
@thinksnews
@thinksnews
on x
Irresponsible corporate choices. They deserve to lose their clients and the suits will cost them. https://techcrunch.com/...
-
@ope_cytes
Ope Cytes
on x
@TechCrunch they have a point - password re-use is a common problem - people who choose to not consider even the most basic security mindset when accessing these online services really need to be held responsible for their own negligence.
-
@immutablechrist
Christopher Gleason
on x
Yes, they are the gullible rubes that trusted BigTech with their DNA and data. No good will come from the theft of people's data, to include their exact DNA makeup. 23andMe needs to be hit with a class action suit that puts them out of business. https://techcrunch.com/...
-
@iethics
@iethics
on x
“#23andMe's lawyers argued that the stolen [genetic and ancestry] #data cannot be used to inflict monetary damage against the victims”: https://techcrunch.com/... #ethics #law #privacy #tech #health #business
-
@securecypher
@securecypher
on x
It is absolutely laughable that @23andMe is trying to blame the victims for THEIR data breach. Like how incompetent can your board, legal, security team be? I hope y'all are BURIED in lawsuits for years. Stay away from this company at all costs. https://techcrunch.com/...
-
@ockfen
Cort
on x
From these 14,000 initial victims, however, the hackers were able to then access the personal data of the other 6.9 million million victims because they had opted-in to 23andMe's DNA Relatives feature. https://techcrunch.com/...
-
@jasonjurotich
Jason Jurotich
on x
And this is why I will no longer use websites without passkeys or @Yubico in 2024. If you don't care about security, don't make a website. https://techcrunch.com/...
-
@andrewtumilty
Andrew Tumilty
on x
I am trying to imagine how quickly our firm would be dropped by a client, if our advice in a crisis communications situation was “have you considered blaming your customers.”
-
@vickerysec
Chris Vickery
on x
It's much easier to understand when you realize that 23andMe has no reason to care about these people. The transaction has happened. The end user is now a liability. 23andMe has the data. There is more profit in spurning their “customers” now. It's perverse, but it's business.
-
@tomboy7000
Tom
on x
BS. If a company does not conduct the best computer security possible, they are liable. I know of a company that left personnel records with social secuirty numbers, birth dates, and names left in plain sight on a desk in the lobby. https://techcrunch.com/...
-
@do_i_feellucky
@do_i_feellucky
on x
The audacity and shamelessness is unbelievable... 23andMe tells victims it's their fault that their data was breached https://techcrunch.com/...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
NEW: 23andMe is blaming customers for the data breach that affected 6.9 million customers. We saw a letter 23andMe sent to a group of victims that is suing the company, which shows what strategy the company will use in these lawsuits: blame the victims. https://techcrunch.com/...