Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Amazon Unveils Slimmer Fire TV Stick HD, Opens Ember Artline TVs for Pre-Order

Wait, could they still break up Live Nation?

Hightouch reaches $100M ARR powered by AI-powered marketing tools

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    OpenAI updates its Agents SDK to help enterprises build safer, more capable agents

    16 April 2026

    Reid Hoffman weighs in on the ‘tokenmaxxing’ debate.

    15 April 2026

    Anthropic’s co-founder confirms the company briefed the Trump administration on Mythos

    15 April 2026

    Microsoft is working on yet another OpenClaw-like agent

    14 April 2026

    OpenAI has acquired AI personal finance startup Hiro

    14 April 2026
  • Apps

    AI learning app Gizmo soars with 13 million users and $22 million in investment

    16 April 2026

    Adobe’s new Firefly AI assistant can use Creative Cloud apps to complete tasks

    15 April 2026

    How the Freecash rewards app made it to the top of the app stores

    15 April 2026

    X brings voice memos back to X Chat

    14 April 2026

    Avec’s Tinder-style email app lets you swipe through your inbox

    14 April 2026
  • Crypto

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025
  • Fintech

    Airwallex is set to take on Stripe and the rest of the payments industry — in the physical world

    16 April 2026

    Cash app launches ‘pay later’ feature for P2P transfers

    3 April 2026

    Doss raises $55 million for AI inventory management that connects to ERP

    24 March 2026

    Despite stiff competition, Kalshi, Polymarket CEOs back $35m VC fund projections

    23 March 2026

    Amid legal turmoil, Kalshi is temporarily banned in Nevada

    20 March 2026
  • Hardware

    Amazon Unveils Slimmer Fire TV Stick HD, Opens Ember Artline TVs for Pre-Order

    16 April 2026

    Motorola is suing social platforms and creators over posts raising concerns about speech in India

    16 April 2026

    AI data center startup Fluidstack is in talks for a $1 billion round at an $18 billion valuation months after raising $7.5 billion, report says

    15 April 2026

    Amazon is ending support for older Kindle devices

    9 April 2026

    Intel signs Elon Musk’s Terafab chip project

    8 April 2026
  • Media & Entertainment

    Wait, could they still break up Live Nation?

    16 April 2026

    HBO Max is coming to India through an exclusive JioHotstar deal

    15 April 2026

    YouTube Live Streams will now withhold ads during peak engagement to protect the atmosphere

    14 April 2026

    X says he’s reducing payouts to clickbait accounts

    12 April 2026

    TechCrunch is headed to Tokyo — and it’s bringing the Startup Battlefield with it

    10 April 2026
  • Security

    Sweden blames Russian hackers for attempted ‘catastrophic’ cyberattack on thermal plant

    15 April 2026

    Adobe fixes PDF zero-day security flaw that hackers have been exploiting for months

    15 April 2026

    Someone planted backdoors in dozens of WordPress plugins used on thousands of websites

    14 April 2026

    Anodot hack leaves over a dozen compromised companies facing extortion

    14 April 2026

    Booking.com confirms that hackers accessed customer data

    13 April 2026
  • Startups

    Hightouch reaches $100M ARR powered by AI-powered marketing tools

    16 April 2026

    StrictlyVC San Francisco is less than a month away

    15 April 2026

    Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

    12 April 2026

    This founder helped build SpaceX’s most powerful rocket engine. Now he’s building a “fighter for orbit.”

    12 April 2026

    Sierra’s Bret Taylor says the era of button-clicking is over

    11 April 2026
  • Transportation

    Ford EV and chief technology officer are leaving the auto industry

    16 April 2026

    Chipmakers AMD, Arm and Qualcomm are investing in this buzzing self-driving technology startup

    15 April 2026

    London is closing in on its first robotaxi service as Waymo begins trials

    15 April 2026

    Tesla adds ‘ribs’, other stats to track how often drivers use Full Self-Driving software

    14 April 2026

    Uber and Nuro begin testing premium robotaxi service in San Francisco

    14 April 2026
  • Venture

    Anthropic rejects VC funding that values ​​it at $800B+, for now

    16 April 2026

    Financial risk management platform Pillar raises $20 million in rounds led by a16z

    15 April 2026

    Vercel CEO Guillermo Rauch signals IPO readiness as AI agents drive revenue

    14 April 2026

    Nvidia-backed SiFive hits $3.65 billion valuation for open AI chips

    11 April 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    10 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»23andMe tells victims it’s their fault their data was breached
Security

23andMe tells victims it’s their fault their data was breached

techtost.comBy techtost.com4 January 202404 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
23andme Tells Victims It's Their Fault Their Data Was Breached
Share
Facebook Twitter LinkedIn Pinterest Email

Facing more than 30 lawsuits from the victims of the massive data breach, 23andMe is now deflecting blame onto the victims themselves in an attempt to absolve itself of any responsibility; according to a letter sent to a victims’ group seen by TechCrunch.

“Instead of acknowledging its role in this data security disaster, 23andMe apparently decided to hang its customers out to dry by downplaying the seriousness of these events,” said Hassan Zavareei, one of the lawyers representing the victims who received the letter from 23andMe. TechCrunch in an email.

In December, 23andMe admitted that hackers had stolen the genetic and ancestry data of 6.9 million users, nearly half of its customers.

The data breach started with the hackers accessing only about 14,000 user accounts. Hackers broke into this first set of victims by brute forcing accounts with passwords known to be associated with the targeted customers, a technique known as credential stuffing.

Of those initial 14,000 victims, however, the hackers were then able to gain access to the personal data of another 6.9 million victims because they had opted in to 23andMe’s DNA congeners feature. This optional feature allows customers to automatically share some of their data with people they consider related to them on the platform.

In other words, by breaking into the accounts of only 14,000 customers, the hackers then breached the personal data of another 6.9 million customers whose accounts were not directly compromised.

But in a letter sent to a group of hundreds of 23andMe users who are now suing the company, 23andMe said “users negligently recycled and failed to update their passwords after these previous security incidents, which are unrelated with 23andMe.”

“Therefore, the incident was not the result of 23andMe’s alleged failure to maintain reasonable security measures,” the letter states.

Zavareei said 23andMe is “shamelessly” blaming victims of the data breach.

“That finger is stupid. 23andMe knew or should have known that many consumers use recycled passwords, and therefore 23andMe should have implemented some of the many safeguards available to protect against credential stuffing — especially considering that 23andMe stores personal information identification, health information and genetic information on its platform. Zavarei said in an email.

“The breach affected millions of consumers whose data was exposed through the DNA Relatives feature on the 23andMe platform, not because they used recycled passwords. Of those millions, only a few thousand accounts were compromised due to credential stuffing. 23andMe’s attempt to avoid responsibility by blaming its customers does nothing for the millions of consumers whose data was breached through no fault of their own,” Zavareei said.

Contact us

Do you have more information about the 23andMe incident? We would love to hear from you. Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or email at lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

In response to 23andMe’s letter, Dante Termohs, a 23andMe customer affected by the data breach, told TechCrunch that he found it “terrifying that 23andMe is trying to hide from the consequences instead of helping its customers.”

Lawyers for 23andMe argued that the stolen data cannot be used to cause financial harm to the victims.

“The potentially accessed information cannot be used for any harm. As explained in the October 6, 2023 blog post, the profile information that may have been accessed is related to the DNA Relatives feature that a customer creates and chooses to share with other users on the 23andMe platform. Such information would only be available if claimants positively choose to share that information with other users through the DNA Relatives feature. Furthermore, the information potentially obtained by the unauthorized actor about the plaintiffs could not have been used to cause property damage (it did not include the social security number, driver’s license number, or any payment or financing information),” the letter said .

23andMe and one of its lawyers did not respond to TechCrunch’s request for comment.

After the breach was disclosed, 23andMe reset all customer passwords and then required all customers to use multi-factor authentication, which was only optional before the breach.

In an effort to pre-empt the inevitable class-action lawsuits and mass arbitration claims, 23andMe changed its terms of service to make it more difficult for victims to join together when filing a legal claim against the company. Lawyers with experience representing data breach victims told TechCrunch that the changes were “cynical,” “self-serving” and “a desperate attempt” to protect and prevent customers from going after the company.

Clearly, the changes didn’t stop what is now an upheaval class actions.

23 and I 23andMe breached cyber security data data breach fault group action hacker Hacking tells victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCloud-native cybersecurity startup Aqua Security raises $60 million and remains a unicorn
Next Article Urbanista integrates Powerfoyle technology with solar-powered headphones
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Sweden blames Russian hackers for attempted ‘catastrophic’ cyberattack on thermal plant

15 April 2026

Adobe fixes PDF zero-day security flaw that hackers have been exploiting for months

15 April 2026

AI data center startup Fluidstack is in talks for a $1 billion round at an $18 billion valuation months after raising $7.5 billion, report says

15 April 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Amazon Unveils Slimmer Fire TV Stick HD, Opens Ember Artline TVs for Pre-Order

16 April 2026

Wait, could they still break up Live Nation?

16 April 2026

Hightouch reaches $100M ARR powered by AI-powered marketing tools

16 April 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Airwallex is set to take on Stripe and the rest of the payments industry — in the physical world

16 April 2026

Cash app launches ‘pay later’ feature for P2P transfers

3 April 2026

Doss raises $55 million for AI inventory management that connects to ERP

24 March 2026
Startups

Hightouch reaches $100M ARR powered by AI-powered marketing tools

StrictlyVC San Francisco is less than a month away

Walmart-owned Flipkart, Amazon are squeezing India’s e-commerce startups

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.