Home Latest 23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews

23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews

0
23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews

[ad_1]

The genetic testing firm 23andMe confirmed on Friday that knowledge from a subset of its customers has been compromised. The firm mentioned its techniques weren’t breached and that attackers gathered the information by guessing the login credentials of a gaggle of customers after which scraping extra folks’s info from a function generally known as DNA Relatives. Users choose into sharing their info by way of DNA Relatives for others to see. 

Hackers posted an preliminary knowledge pattern on the platform BreachForums earlier this week, claiming that it contained 1 million knowledge factors completely about Ashkenazi Jews. There additionally appear to be tons of of hundreds of customers of Chinese descent impacted by the leak. On Wednesday, the actor started promoting what it claims are 23andMe profiles for between $1 and $10 per account, relying on the size of the acquisition. The knowledge consists of issues like a show identify, intercourse, start 12 months, and a few particulars about genetic ancestry outcomes, like that somebody is, say, of “broadly European” or “broadly Arabian” descent. It may additionally embody some extra particular geographic ancestry info. The info doesn’t seem to incorporate precise, uncooked genetic knowledge.

The firm emphasised in a press release that it doesn’t see proof that its techniques have been breached. It additionally inspired customers to make use of sturdy, distinctive passwords and allow two-factor authentication to maintain attackers from compromising their particular person accounts utilizing login credentials uncovered in different knowledge breaches.

“We were made aware that certain 23andMe customer profile information was compiled through access to individual 23andMe.com accounts,” the corporate mentioned in a press release. “We believe that the threat actor may have then, in violation of our terms of service, accessed 23andme.com accounts without authorization and obtained information from those accounts.” 

The firm has not been clear on whether or not it has validated the information the risk actor leaked, noting that its investigation is ongoing and that it at present has “preliminary results.” A spokesperson for the corporate advised WIRED that the leaked info is according to a scenario wherein some consumer accounts had been uncovered after which leveraged to scrape knowledge seen in DNA Relatives. But when pressed on the small print of whether or not the information has been validated, the spokesperson mentioned that verifying the information is pending and that the corporate can’t at present affirm whether or not the leaked info is actual.

This level is critical each for everybody whose info might have been compromised and since the information posted by the actor claims to incorporate “celebrities.” Entries for technologists Mark Zuckerberg, Elon Musk, and Sergey Brin are all seen within the pattern knowledge, together with “Profile ID,” “Account ID,” identify, intercourse, start 12 months, present location, and fields generally known as “ydna” and “ndna.” It is unclear if the information for these entries is professional or was inserted. For instance, Musk and Brin seem to have the identical profile and account IDs within the leak.

[adinserter block=”4″]

[ad_2]

Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here