Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Ultrahuman boosts US push with Ring Pro as Oura tightens its grip

Delve halts demos, Insight Partners sheds investment position amid ‘false compliance’ claims

Bengaluru food delivery startup Swish raises $38 million, its third round in 18 months

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Bernie Sanders’ AI ‘gotcha’ video fails, but the memes are great

    24 March 2026

    Are AI tokens the new signing bonus or just a cost of doing business?

    23 March 2026

    Want to build a robot snowman?

    23 March 2026

    Why Wall Street Didn’t Win Nvidia’s Big Conference

    22 March 2026

    New court filing reveals Pentagon told Anthropic the two sides were nearly aligned — a week after Trump declared his relationship

    21 March 2026
  • Apps

    Apple Maps may receive advertisements

    24 March 2026

    Facebook is launching a new monetization program to attract popular creators from TikTok, YouTube

    23 March 2026

    Apps that distract you from the endless cycle of scrolling

    23 March 2026

    The features powered by Gemini in Google Workspace that are worth using

    22 March 2026

    Meta finally decides not to close Horizon Worlds in VR

    22 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026

    Nominations for the Startup Battlefield 200 are still open

    19 March 2026

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026

    Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

    16 March 2026
  • Hardware

    Ultrahuman boosts US push with Ring Pro as Oura tightens its grip

    24 March 2026

    Amazon is working on a new smartphone with Alexa at its core, the report says

    20 March 2026

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026

    MacBook Neo, AirPods Max 2, iPhone 17e and everything else Apple announced this month

    18 March 2026

    Oura enters India’s smart ring market with Ring 4

    17 March 2026
  • Media & Entertainment

    Tubi joins forces with popular TikTokers to create original streaming content

    19 March 2026

    Patreon CEO calls AI companies’ fair use argument ‘bogus’, says creators should be paid

    18 March 2026

    Meet Vurt, the first mobile streaming platform for indie filmmakers embracing vertical video

    18 March 2026

    BuzzFeed debuts AI applications for new revenue

    17 March 2026

    Facebook makes it easy for creators to report copycats

    14 March 2026
  • Security

    Delve halts demos, Insight Partners sheds investment position amid ‘false compliance’ claims

    24 March 2026

    The FBI says Iranian hackers are using Telegram to steal data in malware attacks

    23 March 2026

    Delve accused of misleading customers with ‘false compliance’

    22 March 2026

    Delve accused of misleading customers with ‘false compliance’

    21 March 2026

    The US accuses the Iranian government of operating a hacktivist group that hacked the Stryker

    20 March 2026
  • Startups

    Bengaluru food delivery startup Swish raises $38 million, its third round in 18 months

    24 March 2026

    Cursor admits that his new coding model was built on top of Moonshot AI’s Kimi

    23 March 2026

    Microsoft hires Sequoia-backed AI collaboration platform team Cove

    21 March 2026

    Consumer-focused privacy firm Cloaked raises $375 million as it expands into the enterprise

    20 March 2026

    Tools for founders to navigate and move past conflicts

    20 March 2026
  • Transportation

    Zipline raises another $200 million to fuel drone delivery expansion

    24 March 2026

    TechCrunch Mobility: Uber everywhere, at once

    23 March 2026

    The SEC ends its four-year investigation into EV startup Faraday Future

    23 March 2026

    Uber taps Rivian to build robotaxis in deal worth up to $1.25 billion

    22 March 2026

    Federal authorities intensify investigation into Tesla’s Full Self-Driving (Supervised) software

    21 March 2026
  • Venture

    Startup Gimlet Labs solves the AI ​​inference problem in a surprisingly elegant way

    24 March 2026

    AI startups are eating up the venture industry, and the returns, so far, are good

    21 March 2026

    Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

    19 March 2026

    AI ‘boys club’ could widen wealth gap for women, says Rana el Kaliouby

    18 March 2026

    Billionaires made a promise – now some want to leave

    17 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»23andMe tells victims it’s their fault their data was breached
Security

23andMe tells victims it’s their fault their data was breached

techtost.comBy techtost.com4 January 202404 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
23andme Tells Victims It's Their Fault Their Data Was Breached
Share
Facebook Twitter LinkedIn Pinterest Email

Facing more than 30 lawsuits from the victims of the massive data breach, 23andMe is now deflecting blame onto the victims themselves in an attempt to absolve itself of any responsibility; according to a letter sent to a victims’ group seen by TechCrunch.

“Instead of acknowledging its role in this data security disaster, 23andMe apparently decided to hang its customers out to dry by downplaying the seriousness of these events,” said Hassan Zavareei, one of the lawyers representing the victims who received the letter from 23andMe. TechCrunch in an email.

In December, 23andMe admitted that hackers had stolen the genetic and ancestry data of 6.9 million users, nearly half of its customers.

The data breach started with the hackers accessing only about 14,000 user accounts. Hackers broke into this first set of victims by brute forcing accounts with passwords known to be associated with the targeted customers, a technique known as credential stuffing.

Of those initial 14,000 victims, however, the hackers were then able to gain access to the personal data of another 6.9 million victims because they had opted in to 23andMe’s DNA congeners feature. This optional feature allows customers to automatically share some of their data with people they consider related to them on the platform.

In other words, by breaking into the accounts of only 14,000 customers, the hackers then breached the personal data of another 6.9 million customers whose accounts were not directly compromised.

But in a letter sent to a group of hundreds of 23andMe users who are now suing the company, 23andMe said “users negligently recycled and failed to update their passwords after these previous security incidents, which are unrelated with 23andMe.”

“Therefore, the incident was not the result of 23andMe’s alleged failure to maintain reasonable security measures,” the letter states.

Zavareei said 23andMe is “shamelessly” blaming victims of the data breach.

“That finger is stupid. 23andMe knew or should have known that many consumers use recycled passwords, and therefore 23andMe should have implemented some of the many safeguards available to protect against credential stuffing — especially considering that 23andMe stores personal information identification, health information and genetic information on its platform. Zavarei said in an email.

“The breach affected millions of consumers whose data was exposed through the DNA Relatives feature on the 23andMe platform, not because they used recycled passwords. Of those millions, only a few thousand accounts were compromised due to credential stuffing. 23andMe’s attempt to avoid responsibility by blaming its customers does nothing for the millions of consumers whose data was breached through no fault of their own,” Zavareei said.

Contact us

Do you have more information about the 23andMe incident? We would love to hear from you. Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or email at lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

In response to 23andMe’s letter, Dante Termohs, a 23andMe customer affected by the data breach, told TechCrunch that he found it “terrifying that 23andMe is trying to hide from the consequences instead of helping its customers.”

Lawyers for 23andMe argued that the stolen data cannot be used to cause financial harm to the victims.

“The potentially accessed information cannot be used for any harm. As explained in the October 6, 2023 blog post, the profile information that may have been accessed is related to the DNA Relatives feature that a customer creates and chooses to share with other users on the 23andMe platform. Such information would only be available if claimants positively choose to share that information with other users through the DNA Relatives feature. Furthermore, the information potentially obtained by the unauthorized actor about the plaintiffs could not have been used to cause property damage (it did not include the social security number, driver’s license number, or any payment or financing information),” the letter said .

23andMe and one of its lawyers did not respond to TechCrunch’s request for comment.

After the breach was disclosed, 23andMe reset all customer passwords and then required all customers to use multi-factor authentication, which was only optional before the breach.

In an effort to pre-empt the inevitable class-action lawsuits and mass arbitration claims, 23andMe changed its terms of service to make it more difficult for victims to join together when filing a legal claim against the company. Lawyers with experience representing data breach victims told TechCrunch that the changes were “cynical,” “self-serving” and “a desperate attempt” to protect and prevent customers from going after the company.

Clearly, the changes didn’t stop what is now an upheaval class actions.

23 and I 23andMe breached cyber security data data breach fault group action hacker Hacking tells victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCloud-native cybersecurity startup Aqua Security raises $60 million and remains a unicorn
Next Article Urbanista integrates Powerfoyle technology with solar-powered headphones
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Delve halts demos, Insight Partners sheds investment position amid ‘false compliance’ claims

24 March 2026

The FBI says Iranian hackers are using Telegram to steal data in malware attacks

23 March 2026

Delve accused of misleading customers with ‘false compliance’

22 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Ultrahuman boosts US push with Ring Pro as Oura tightens its grip

24 March 2026

Delve halts demos, Insight Partners sheds investment position amid ‘false compliance’ claims

24 March 2026

Bengaluru food delivery startup Swish raises $38 million, its third round in 18 months

24 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

23 March 2026

Amid legal turmoil, Kalshi is temporarily banned in Nevada

20 March 2026

Nominations for the Startup Battlefield 200 are still open

19 March 2026
Startups

Bengaluru food delivery startup Swish raises $38 million, its third round in 18 months

Cursor admits that his new coding model was built on top of Moonshot AI’s Kimi

Microsoft hires Sequoia-backed AI collaboration platform team Cove

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.