23andMe admits hackers stole raw genotype data - and that cyberattack went undetected for months | Firm says it didn't realize customers were being hacked
Firm says it didn't realize customers were being hacked
23andMe admits hackers stole raw genotype data - and that cyberattack went undetected for months | Firm says it didn't realize customers were being hacked::Firm says it didn't realize customers were being hacked
Our investigation determined the threat actor downloaded or accessed your uninterrupted raw genotype data, and may have
accessed other sensitive information in your account,
Fascinating. I was under the impression that you couldn't get that without having it sent to your email address. I certainly haven't seen any other ways of getting raw genomics out.
Is this that the threat actor sent it to an email that was potentially compromised or do they have download logs of some form of hidden direct download feature?
They wouldn't need to access 14,000 separate accounts if they had internal access to the database.
The article states they got access to "private data" from 6.9 million other users via a 'DNA relatives' feature but doesn't explain what kind of information that is. For those accounts that got directly accessed, it seems unlikely the hackers requested and intercepted an email for every one without being noticed sooner. Sounds like they only scraped what's available on the site itself but it'd be nice if the article actually detailed that.