23andMe zahlt $30 Millionen im Rahmen eines Vergleichs zum Verstoß gegen den Datenschutz in der Genetik

Teilen:

DNA testing giant 23andMe has agreed to pay $30 million to settle a lawsuit over a data breach that exposed the personal information of 6.4 million customers in 2023.

The proposed class action settlement, filed Thursday in a San Francisco federal court and awaiting judicial approval, includes cash payments for affected customers, which will be distributed within ten days of final approval.

“23andMe believes the settlement is fair, adequate, and reasonable,” the company said in a memorandum filed Friday.

23andMe has also agreed to strengthen its security protocols, including protections against credential-stuffing attacks, mandatory two-factor authentication for all users, and annual cybersecurity audits.

The company must also create and maintain a data breach incident response plan and stop retaining personal data for inactive or deactivated accounts. An updated Information Security Program will also be provided to all employees during annual training sessions.

“23andMe denies the claims and allegations set forth in the Complaint, denies that it failed to properly protect the Personal Information of its consumers and users, and further denies the viability of Settlement Class Representatives’ claims for statutory damages,” the company said in the filed preliminary settlement.

“23andMe denies any wrongdoing whatsoever, and this Agreement shall in no event be construed or deemed to be evidence of or an admission or concession on the part of 23andMe with respect to any claim of any fault or liability or wrongdoing or damage whatsoever.

ADVERTISING

This settlement addresses claims that the genetic testing company failed to safeguard users’ privacy and neglected to inform customers that hackers specifically targeted them and their information was reportedly offered for sale on the dark web.

Data stolen following credential-stuffing attack

In October 2023, 23andMe revealed that unauthorized access to customer profiles occurred through compromised accounts. Hackers exploited credentials stolen from other breaches to access 23andMe accounts.

After discovering the breach, the company implemented measures to block similar incidents, including requiring customers to reset passwords and enabling two-factor authentication by default starting in November.

Starting in October, threat actors leaked data profiles belonging to 4.1 million individuals in the United Kingdom and 1 million Ashkenazi Jews on the unofficial 23andMe subreddit and hacking forums like BreachForums.

23andMe told BleepingComputer in December that data for 6.9 million customers, including information on 6.4 million U.S. residents, was downloaded in the breach.

In January, the company also confirmed that attackers stole health reports and raw genotype data over a five-month credential-stuffing attack from April to September.

The data breach led to multiple class-action lawsuits, prompting 23andMe to amend its Terms of Use in November 2023, a move criticized by customers. The company later clarified that the changes aimed to simplify the arbitration process.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:38 pm, Jan. 24, 2025
Wetter-Symbol 8°C
L: 7° | H: 9°
overcast clouds
Luftfeuchtigkeit: 74 %
Druck: 1000 mb
Wind: 7 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:49 am
Sonnenuntergang: 4:35 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 9°°C 0 mm 0% 8 mph 74 % 1000 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 8°°C 1 mm 100% 7 mph 93 % 1010 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 8°°C 0 mm 0% 8 mph 74 % 1000 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
7° | 8°°C 0 mm 0% 5 mph 77 % 1000 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 7°°C 0 mm 0% 4 mph 85 % 999 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 1 mm 100% 7 mph 93 % 1001 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€101,411.74
1.61%
Ethereum(ETH)
€3,233.23
5.50%
XRP(XRP)
€3.00
2.38%
Fesseln(USDT)
€0.95
0.00%
Solana(SOL)
€250.52
6.08%
Dogecoin(DOGE)
€0.342785
3.58%
USDC(USDC)
€0.95
0.00%
Shiba Inu(SHIB)
€0.000019
2.71%
Pepe(PEPE)
€0.000015
7.69%
Peanut das Eichhörnchen(PNUT)
€0.341906
3.03%
Nach oben scrollen