Comment on 23andMe tells victims it's their fault that their data was breached | TechCrunch

<- View Parent
dpkonofa@lemmy.world ⁨10⁩ ⁨months⁩ ago

This wasn’t a brute force attack, though. Even if they had brute force detection, which I’m not sure if they don’t or not, that would have done nothing to help this situation as nothing was brute forced in the way that would have been detected. The attempts were spread out over months using bots that were local to the last good login location. That’s the primary issue here. The logins looked legitimate. It wasn’t until after the exposure that they knew it wasn’t and that was because of other signals that 23andMe obviously had in place (I’m guessing usage patterns or automation detection).

source
Sort:hotnewtop