Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

China’s Moonshot AI Raises $2B in $20B Valuation as Demand for Open Source AI Soars

GM agrees to pay $12.75 million in California driver privacy settlement

Voice AI in India is difficult. Wispr Flow is betting on it anyway.

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Voice AI in India is difficult. Wispr Flow is betting on it anyway.

    10 May 2026

    Cloudflare Says AI Made 1,100 Jobs Obsolete Even As Revenue Hits Record High

    9 May 2026

    Fired Oracle workers tried to negotiate better severance. Oracle said no.

    9 May 2026

    Last 24 hours to get 50% off a second pass to Disrupt 2026 | TechCrunch

    8 May 2026

    OpenAI is launching new voice intelligence capabilities in its API

    8 May 2026
  • Apps

    Tinder Match Group owner slows hiring to pay for increased use of AI tools

    10 May 2026

    Bumble is getting rid of the beat, CEO says

    9 May 2026

    Truecaller cuts 70 jobs amid declining ad sales

    8 May 2026

    Perplexity PC is now available to everyone on Mac

    8 May 2026

    Startup Battlefield 200 applications close on May 27

    7 May 2026
  • Crypto

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025
  • Fintech

    Fintech startup Parker files for bankruptcy

    10 May 2026

    Robinhood’s venture fund IPO attracted 150,000+ private investors, CEO says

    7 May 2026

    PayPal says it’s “becoming a tech company again” — that’s AI

    6 May 2026

    Stripe introduces Link, a digital wallet that autonomous AI agents can also use

    1 May 2026

    Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

    1 May 2026
  • Hardware

    The Instax Wide 400 takes the simplicity of instant photography and expands it, literally

    10 May 2026

    Google Unveils Fitbit Air Without Whoop-like Display

    8 May 2026

    Google’s $9.99 per month AI health plan launches on May 19

    8 May 2026

    Apple to pay $250 million to settle lawsuit over Siri’s lagging AI features

    7 May 2026

    reMarkable’s new Paper Pure tablet goes back to basics with a monochrome display

    6 May 2026
  • Media & Entertainment

    Netflix delays Greta Gerwig’s ‘Narnia’ for big theatrical push to 2027

    2 May 2026

    Roku’s $3 streaming service Howdy hits 1 million subscribers, per recent report

    29 April 2026

    Australia forces Big Tech companies to pay for news or face 2.25% tax.

    28 April 2026

    India’s app market is booming — but global platforms are raking in most of the profits

    23 April 2026

    YouTube extends its AI similarity detection technology to celebrities

    21 April 2026
  • Security

    How Anthropic’s Mythos has rewritten Firefox’s approach to cyber security

    9 May 2026

    US defense contractor who sold hacking tools to Russian broker ordered to pay $10 million to former employers

    9 May 2026

    Poland says hackers breached water treatment plants, and the US faces the same threat

    8 May 2026

    Hackers deface school login pages after claiming another Instructure hack

    8 May 2026

    Hackers hack victims who have been hacked by other hackers

    7 May 2026
  • Startups

    China’s Moonshot AI Raises $2B in $20B Valuation as Demand for Open Source AI Soars

    10 May 2026

    Could Lovable’s automatic 10% pay rise be the cure for toxic cultures?

    9 May 2026

    Gusto hits $1 billion in revenue, moves closer to public markets

    9 May 2026

    Learn what it takes to raise a Series A in 2027 at Disrupt 2026

    8 May 2026

    Voi founders’ new AI startup Pit has become the latest rising star from Stockholm

    8 May 2026
  • Transportation

    GM agrees to pay $12.75 million in California driver privacy settlement

    10 May 2026

    Uber partner Avride is under investigation for self-driving accidents

    9 May 2026

    Bicycle electronics subsidiaries, battery, Porsche rolls as part of company overhaul

    9 May 2026

    Lime, the Uber-backed micromobility company, files for an IPO

    8 May 2026

    Kodiak AI raises $100M in deep discount, sending stock down 37%

    8 May 2026
  • Venture

    Mother Ventures looks at moms as the ‘economic engine’

    9 May 2026

    2 days left: Get 50% off a second Disrupt 2026 pass

    7 May 2026

    All your M&A questions will be answered at Disrupt 2026

    6 May 2026

    ElevenLabs lists BlackRock, Jamie Foxx and Eva Longoria as new investors

    6 May 2026

    Get 50% off a second Disrupt 2026 pass to bid more, faster

    5 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»23andMe tells victims it’s their fault their data was breached
Security

23andMe tells victims it’s their fault their data was breached

techtost.comBy techtost.com4 January 202404 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
23andme Tells Victims It's Their Fault Their Data Was Breached
Share
Facebook Twitter LinkedIn Pinterest Email

Facing more than 30 lawsuits from the victims of the massive data breach, 23andMe is now deflecting blame onto the victims themselves in an attempt to absolve itself of any responsibility; according to a letter sent to a victims’ group seen by TechCrunch.

“Instead of acknowledging its role in this data security disaster, 23andMe apparently decided to hang its customers out to dry by downplaying the seriousness of these events,” said Hassan Zavareei, one of the lawyers representing the victims who received the letter from 23andMe. TechCrunch in an email.

In December, 23andMe admitted that hackers had stolen the genetic and ancestry data of 6.9 million users, nearly half of its customers.

The data breach started with the hackers accessing only about 14,000 user accounts. Hackers broke into this first set of victims by brute forcing accounts with passwords known to be associated with the targeted customers, a technique known as credential stuffing.

Of those initial 14,000 victims, however, the hackers were then able to gain access to the personal data of another 6.9 million victims because they had opted in to 23andMe’s DNA congeners feature. This optional feature allows customers to automatically share some of their data with people they consider related to them on the platform.

In other words, by breaking into the accounts of only 14,000 customers, the hackers then breached the personal data of another 6.9 million customers whose accounts were not directly compromised.

But in a letter sent to a group of hundreds of 23andMe users who are now suing the company, 23andMe said “users negligently recycled and failed to update their passwords after these previous security incidents, which are unrelated with 23andMe.”

“Therefore, the incident was not the result of 23andMe’s alleged failure to maintain reasonable security measures,” the letter states.

Zavareei said 23andMe is “shamelessly” blaming victims of the data breach.

“That finger is stupid. 23andMe knew or should have known that many consumers use recycled passwords, and therefore 23andMe should have implemented some of the many safeguards available to protect against credential stuffing — especially considering that 23andMe stores personal information identification, health information and genetic information on its platform. Zavarei said in an email.

“The breach affected millions of consumers whose data was exposed through the DNA Relatives feature on the 23andMe platform, not because they used recycled passwords. Of those millions, only a few thousand accounts were compromised due to credential stuffing. 23andMe’s attempt to avoid responsibility by blaming its customers does nothing for the millions of consumers whose data was breached through no fault of their own,” Zavareei said.

Contact us

Do you have more information about the 23andMe incident? We would love to hear from you. Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or email at lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

In response to 23andMe’s letter, Dante Termohs, a 23andMe customer affected by the data breach, told TechCrunch that he found it “terrifying that 23andMe is trying to hide from the consequences instead of helping its customers.”

Lawyers for 23andMe argued that the stolen data cannot be used to cause financial harm to the victims.

“The potentially accessed information cannot be used for any harm. As explained in the October 6, 2023 blog post, the profile information that may have been accessed is related to the DNA Relatives feature that a customer creates and chooses to share with other users on the 23andMe platform. Such information would only be available if claimants positively choose to share that information with other users through the DNA Relatives feature. Furthermore, the information potentially obtained by the unauthorized actor about the plaintiffs could not have been used to cause property damage (it did not include the social security number, driver’s license number, or any payment or financing information),” the letter said .

23andMe and one of its lawyers did not respond to TechCrunch’s request for comment.

After the breach was disclosed, 23andMe reset all customer passwords and then required all customers to use multi-factor authentication, which was only optional before the breach.

In an effort to pre-empt the inevitable class-action lawsuits and mass arbitration claims, 23andMe changed its terms of service to make it more difficult for victims to join together when filing a legal claim against the company. Lawyers with experience representing data breach victims told TechCrunch that the changes were “cynical,” “self-serving” and “a desperate attempt” to protect and prevent customers from going after the company.

Clearly, the changes didn’t stop what is now an upheaval class actions.

23 and I 23andMe breached cyber security data data breach fault group action hacker Hacking tells victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCloud-native cybersecurity startup Aqua Security raises $60 million and remains a unicorn
Next Article Urbanista integrates Powerfoyle technology with solar-powered headphones
bhanuprakash.cg
techtost.com
  • Website

Related Posts

How Anthropic’s Mythos has rewritten Firefox’s approach to cyber security

9 May 2026

US defense contractor who sold hacking tools to Russian broker ordered to pay $10 million to former employers

9 May 2026

Poland says hackers breached water treatment plants, and the US faces the same threat

8 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

China’s Moonshot AI Raises $2B in $20B Valuation as Demand for Open Source AI Soars

10 May 2026

GM agrees to pay $12.75 million in California driver privacy settlement

10 May 2026

Voice AI in India is difficult. Wispr Flow is betting on it anyway.

10 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Fintech startup Parker files for bankruptcy

10 May 2026

Robinhood’s venture fund IPO attracted 150,000+ private investors, CEO says

7 May 2026

PayPal says it’s “becoming a tech company again” — that’s AI

6 May 2026
Startups

China’s Moonshot AI Raises $2B in $20B Valuation as Demand for Open Source AI Soars

Could Lovable’s automatic 10% pay rise be the cure for toxic cultures?

Gusto hits $1 billion in revenue, moves closer to public markets

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.