In October, a threat actor attempted to sell 23andMe customer data and, after failing to do so, leaked the data for 1 million Ashkenazi Jews and 4.1 million people living in the United Kingdom.
23andMe told BleepingComputer that the data was obtained through credential stuffing attacks to breach customer accounts.
Using these limited numbers of accounts, the threat actors used the 'DNA Relatives' feature to scrape millions of individuals' data.
In a recent update, 23andMe told BleepingComputer that a total of 6.9 million people were impacted by the breach - 5.5 million through the DNA Relatives feature and 1.4 million people through the Family Tree feature.
Those who send an email disputing the update will remain on the previous Terms of Service.
23andMe hit with lawsuits after hacker leaks stolen genetics data.
Pharmacy provider Truepill data breach hits 2.3 million customers.
Navy contractor Austal USA confirms cyberattack after data leak.
Dollar Tree hit by third-party data breach impacting 2 million people.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 07 Dec 2023 21:45:07 +0000