23andMe Didn’t Notice That They Got Pwned For Five Months…. WTF??

So if you haven’t been keeping track of the ongoing story of 23andMe being pwned in epic fashion, here’s a quick update:

Let’s fast forward to today. According to a filing that was sent to California’s attorney general, the hack actually started in April 2023 and continued until September. That’s five months. Five months where threat actors were able to do their evil work. And what’s worse than that is the fact that 23andMe only found out about this when the threat actors started posting the data on the unofficial subreddit for 23andMe. Now it’s pretty bad when you get pwned. It’s worse when you don’t know about it for months and you only find out about it because someone was browsing Reddit. Which to me suggests that 23andMe was seriously asleep at the switch. 23andMe seriously needs to be sued out of existence because this is frankly unacceptable. And this level of #fail needs to be punished severely.

One Response to “23andMe Didn’t Notice That They Got Pwned For Five Months…. WTF??”

  1. […] that I have about this is that they discovered that they were pwned within a week. While not nearly as bad as 23andMe who were pwned for months before they found out, it highlights that if you can’t keep the bad guys out, at least you should be able to detect […]

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading