jetton, to random
@jetton@mastodon.online avatar

23andMe was hacked and DNA records of 7 million people were compromised. Originally they said it was 14,000.

They just sent out an innocuous sounding email about change in Terms of Service.

If you do not respond rejecting the change, you will give up the ability to be part of the class action lawsuits that are being filed, or take action in court against them.

They sent this out before they are notifying those whose data were breached.

Strongly recommend you opt out of the change.

rvawonk, to Cybersecurity

Genetic testing company 23AndMe confirmed that it suffered a data breach in what appears to be a targeted attack on Jews & Chinese people. Hackers have put up for sale 1 million data points about Ashkenazi Jews, plus hundreds of thousands of Chinese users.

The breach allegedly includes celebrities like Mark Zuckerberg, Elon Musk, and Sergey Brin. #cybersecurity #databreach #23andme
https://www.wired.com/story/23andme-credential-stuffing-data-stolen/

dave_andersen, to random
@dave_andersen@hachyderm.io avatar

Well that's fucking sleazy, but not surprising: #23andme just mailed out a "hey we're changing our ToS (to screw your ability to file a class-action lawsuit against us because of our breach) and if you don't do anything, YOU AGREE TO IT".. before actually notifying customers whether they're part of the 6.9 million breached accounts.

(I have told them to soak their heads.)

LyleDAL, to legal

The #23AndMe data breach is way bigger than originally let on. 7 million customer records were compromised.

The company just sent out an innocuous sounding email about changes in there Terms of Service.

If you do not respond rejecting the change, you will give up the ability to be part of any class action lawsuits that are being filed, or take action in court against them.

They sent this out before they are notifying those whose data were breached.

Strongly recommend you opt out of the change.

#DataBreach #Legal

mattburgess, to Cybersecurity

Genetic testing firm 23andMe has suffered a data breach.

1 million data points exclusively about Ashkenazi Jews have been advertised for sale on a cybercrime forum. There's also information about hundreds of thousands of users of Chinese descent.

It appears to be a credential stuffing attack—where previously leaked logins and passwords from other sites are tried on 23andMe—with the attackers then scraping data from profiles

@lhn's story has all the details we know so far:
https://www.wired.com/story/23andme-credential-stuffing-data-stolen/

HillClimber, to random

For all of those using #23andMe or similar services, here's a periodic reminder on how to properly protect your #biometrics DNA #2fa factors:

  1. Regularly (at least once a year,) change your genetic code. Small random mutations are insufficient, a new code should be generated.

  2. Never use the same genetic code on more than one service.

  3. Select a strong genetic code. Use at least 8 great-grandparents, and at least 1 billion base pairs.

  4. Never share your genetic code with anyone. We will not ask for your genetic code, and giving your genetic code to a co-worker or friend can result in disciplinary actions, including infectious diseases, romantic angst, and unwanted lifetime financial and caregiving responsibilities.

Stay safe out there!

Ruth_Mottram, to Facebook

The really awful thing about #23andMe and their ilk is that while you can choose not to do your own test, close family members can and probably will (just look at how families typically behave on #Facebook for example) and then your data is quite easily determinable too.

A good summary from @carnage4life
https://mas.to/@carnage4life/111194881886981667

the_blackwell_ninja, to random
@the_blackwell_ninja@mastodon.online avatar

If #23AndMe hadn't been storing reams of genetic information on its users indefinitely in the first place, that information wouldn't be in the hands of bad actors now. This rampant uncontrolled data collection by big tech companies needs to stop.

ToSDR, to privacy

23andMe just updated their terms of service

limiting the time in which users can take legal action and adding a class action waver.
If you are a 23andMe user you have 30 days to opt-out. This comes after millions of user data including DNA was leaked.

https://www.23andme.com/legal/terms-of-service/full-version/
@Privacy #privacy #TOS #TOSWatch #TOSDR #23andMe

Peternimmo, to random
@Peternimmo@mastodon.scot avatar

A #genetic testing company, #23andMe, has had a data breach. As the days go by, the extent of the breach seems to get wider. Millions of people have had enormous amounts of personal #data stolen
https://www.wired.com/story/23andme-breach-sec-update/

Bmixed, to Cybersecurity
Dremmwel, to random French
@Dremmwel@mamot.fr avatar

célèbre boîte privée de recherche de parenté génétique, s'est fait pirater.
Les données génétiques, le nom, le prénom et le sexe de milliers de personnes ayant un héritage (génétique) ashkénaze a fuité sur le web il y a quelques jours.
What could possibly go wrong ?

Déjà que payer pour qu'une boîte privée stocke ton ADN aux US c'est un peu une idée mauvaise sur les bords, mais pour faire du fichage ethnique, c'est parfait !

https://www.nbcnews.com/news/us-news/23andme-user-data-targeting-ashkenazi-jews-leaked-online-rcna119324

bespacific, to privacy
@bespacific@newsie.social avatar

GSK Plc will pay Holding Co. $20M for company’s vast of , extending a 5 yr collaboration that’s allowed the to mine as it researches new . Under the new agreement, 23andMe will provide GSK with one year of access to anonymized data from the approximately 80% of gene-testing customers who have agreed to share their information for research. Really? https://www.bloomberg.com/news/articles/2023-10-30/23andme-will-give-gsk-access-to-consumer-dna-data

BenjaminHCCarr, to random
@BenjaminHCCarr@hachyderm.io avatar

#23andMe changes to #termsofservice are 'cynical' and 'self-serving,’ lawyers say
23andMe wants to deter customers from filing both #classaction #lawsuits as well as mass arbitration demands. This is a result of a #databreach that leaked millions of users records.
https://techcrunch.com/2023/12/11/23andme-changes-to-terms-of-service-are-cynical-and-self-serving-lawyers-say/ #CYA

BigAngBlack, to random
@BigAngBlack@fosstodon.org avatar

Sneaky Muthaf****s

After hack, #23andMe gives users 30 days to opt out of #class-action waiver | Ars Technica

https://arstechnica.com/tech-policy/2023/12/23andme-changes-arbitration-terms-after-hack-impacting-millions/

> Anyone who fails to opt out "will be deemed to have agreed to the new terms."

TechDesk, to privacy
@TechDesk@flipboard.social avatar

Following the breach of 6.9 million 23andMe users, the DNA and ancestry company has changed its terms of service. Axios asks a law expert whether the change will protect them from customers who might wish to take legal action.

https://flip.it/T215DC

thenewoil, to privacy
tml, to random
@tml@urbanists.social avatar

Sure, the #23andMe leak was bad, but seriously, if people are afraid that something bad might happen if their #DNA got leaked, I wonder whether they really honestly believe that their DNA is a "secret"?

Just like fingerprints, you leave your DNA everywhere you go.

It has never been a problem for suitably motivated and resourced actors to get your DNA. Or #fingerprint. Unless you are extremely motivated to keep both secret, but in that case you wouldn't have used 23andMe, would you?

DrewNaylor, to random
@DrewNaylor@mastodon.online avatar

Oh boy, victim blaming! That'll make everyone who was in the data breach feel better! Do not use biometrics to log in, you can't change your iris or fingerprint, your fingerprint isn't as unique as everyone thought, and cops can force you to unlock a device locked with biometrics but not pin/password.

https://www.businessinsider.com/23andme-data-breach-victims-responsibility-not-updating-passwords-2024-1

obeto, to random
@obeto@mas.to avatar

Wow!.

Just, wow!

Actually, it really is the fault of #23andMe customers....for using that service in the first place! https://techcrunch.com/2024/01/03/23andme-tells-victims-its-their-fault-that-their-data-was-breached/

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

➝ 🇺🇸 🖼️ MAJOR US SUFFER FALLOUT
➝ 🇪🇸 📡 A “ridiculously weak“ password causes disaster for ’s No. 2 mobile carrier
➝ 🔓 🧬 tells victims it’s their fault that their data was breached
➝ 🔓 💸 loses $86 million in the last hack of 2023
➝ 🔓 🅿️ Europe’s Largest Parking App Provider Informs Customers of Data Breach
➝ 💸 🙊 wallet founder loses $125,000 to fake airdrop website
➝ 🇺🇸 ⚖️ US Says 19 People Charged Following 2019 Takedown of Cybercrime Marketplace
➝ 🇵🇸 🇮🇱 Palestinian Hackers Hit 100 Israeli Organizations in Destructive Attacks
➝ 🔓 ❌ Hacked X Account Abused for Theft
➝ 🇳🇬 🇺🇸 ⚖️ Nigerian hacker arrested for stealing $7.5M from charities
➝ 🇦🇱 📡 Albanian Parliament and One Albania Telecom Hit by Cyber Attacks
➝ 🇺🇸 The FBI is adding more cyber-focused agents to U.S. embassies
➝ 🇺🇸 ⚖️ Former admin to be jailed until Jan. 19 sentencing
➝ 🇺🇸 💰 DOJ Slams with $10 Million Fine Over Massive Illegal Robocall Operation
➝ 📷 🥸 Contractor Pays Parents $50 to Scan Their Childrens' Faces
➝ 💰 🥸 Google Settles $5 Billion Lawsuit Over Tracking Users in 'Incognito Mode'
➝ 🇨🇳 🗳️ to reveal Chinese election interference after Saturday’s vote
➝ 🦠 💰 Settles Insurance Claim, Leaving Definition Unresolved
➝ 🦠 🇰🇵 SpectralBlur: New Backdoor Threat from North Korean Hackers
➝ 🦠 🐍 3 Malicious Packages Found Targeting with Crypto Miners
➝ 🦠 🎠 New Bandook Variant Resurfaces, Targeting Machines
➝ 🦠 🎠 UAC-0050 Group Using New Tactics to Distribute Remcos RAT
➝ 🦠 🇺🇦 CERT-UA Uncovers New Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
➝ 🔓 🦠 Free Decryptor Released for Ransomware
➝ 🐛 📨 Smuggling: New Flaw Lets Attackers Bypass Security and Spoof
➝ 🩹 warns critical EPM lets hackers hijack enrolled devices
➝ 🩹 Google Patches Six Vulnerabilities With First Update of 2024
➝ 🩹 🐡 Millions still haven’t patched SSH protocol

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-012024

LMGsecurity, to Cybersecurity

Watch our new video case study on how attackers gained access the personal data of 6.9 million #23andMe users without compromising the company directly. We'll share what happened and the new implications for organizations: https://youtu.be/B-5Y72UWWhI
#databreach #cybersecurity #CISO

bespacific, to Jewish
@bespacific@newsie.social avatar

#23andMe #Breach Targeted #Jewish and #Chinese Customers, #Lawsuit Says. The #classaction suit said the #genetic testing company failed to notify customers whose personal information was compiled into “curated” lists that were sold on the #darkweb. https://www.yahoo.com/lifestyle/lawsuit-says-23andme-hackers-targeted-users-with-chinese-and-ashkenazi-jewish-heritage-132423486.html #privacy #DataPrivacy #cybercrime

avoidthehack, to privacy

23andMe data breach: stole raw genotype data, health reports

Ugh, so after blaming other people for this breach, 23andMe admits that raw genotype data (which, btw is immutable as it gets for data points) was compromised… due to a 5-month long credential stuffing campaign.

https://www.bleepingcomputer.com/news/security/23andme-data-breach-hackers-stole-raw-genotype-data-health-reports/

BenjaminHCCarr, to Health
@BenjaminHCCarr@hachyderm.io avatar

#23andMe data #breach: Hackers stole raw #genotype data, #health reports
The #credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms. https://www.bleepingcomputer.com/news/security/23andme-data-breach-hackers-stole-raw-genotype-data-health-reports/

Please get a #passwordmanager like #bitwarden. And please for the of all that is holy so #passwordreuse

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines