User data stolen from genetic testing giant 23andMe is now for sale on the dark web::User data from 23andMe accounts has been leaked and put up for sale on a dark web forum after what appeared to be a “credential stuffing” cyberattack.
Well… that data was not in safe hands in the beginning considering facts that the whole company has very close ties to Alphabet and Google.
huginn@feddit.it 1 year ago
Note: this was from password stuffing and is only profile data, not genetic.
Your genomics can only be downloaded from a link sent to your email account.
Don’t reuse your passwords.
The only thing 23andme could have done to prevent this is 2fa.
Saik0Shinigami@lemmy.saik0.com 1 year ago
Not true. It’s easy to detect hundreds of thousands of logins from VPN locations. Or parse that someone is logging in from thousands of miles away from their profile location and send an email. There’s many simple things to implement that they could have done to protect your account with them. They took the easy route.
While the User does bare most of the blame, claiming that 23andme couldn’t do anything else is strictly wrong.
huginn@feddit.it 1 year ago
Preventing these kinds of attacks is a nontrivial problem space and is the exact reason why scraping services are a lucrative business.
It is not trivial to prevent dark web actors from using botnets to make requests and it is comparatively inexpensive to access botnets as a service.
Sending emails for suspicious login is 2fa, by the way.
hansl@lemmy.world 1 year ago
Or, and hear me out, don’t reuse passwords.
nnjethro@lemmy.world 1 year ago
That’s what users could have done, not the site.