Just three years ago, DNA testing company 23andMe was the golden child of Wall Street and Main Street. Today, the company is struggling to remain listed on the Nasdaq.
No, they’ve been heading south for years. I would have loved for it to be a drop in response to the data breach, but this was just a company that was run incompetently.
Cmon, we know their target market was dumbasses. How many dumbasses do you know that use mfa, or that actually look at a login notification before hitting “yes, it’s me”?
Credential stuffing is a well understood part of the threat landscape that 23 and me negligently failed to account for, allowing hackers to access 7 million people’s info after hacking only 14 thousand users.
Refreshing to have some sort of consequences for being negligent with people’s data
Too bad the consequences are not prison.
No, they’ve been heading south for years. I would have loved for it to be a drop in response to the data breach, but this was just a company that was run incompetently.
Which data were they negligent with? I thought it was breaches on other sites that gave reused passwords.
There are still all kinds of things a company can do to mitigate at least some of this. New browser, new location, forced two-factor auth, etc.
Cmon, we know their target market was dumbasses. How many dumbasses do you know that use mfa, or that actually look at a login notification before hitting “yes, it’s me”?
Credential stuffing is a well understood part of the threat landscape that 23 and me negligently failed to account for, allowing hackers to access 7 million people’s info after hacking only 14 thousand users.