PrivacySignal
Breach

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

HIPAA Journal · · US Federal · Data Breaches

23andMe, now operating as Chrome Holding Co., has agreed to an $18 million settlement with a coalition of 42 state attorneys general stemming from a data breach that exposed customer information. The multistate action represents one of the more significant coordinated enforcement responses to a consumer genetic data incident.

Why this matters: Genetic data is not like a leaked password you can reset. It reveals ancestry, health risks, and biological family — information that is permanently yours and permanently sensitive. Millions of people trusted 23andMe with some of the most personal data that exists. The company then suffered a breach, went through bankruptcy, and changed hands. Eighteen million dollars spread across 42 states is not a serious deterrent for a company sitting on that kind of data. The harder question is what happens to all that DNA now that a new company owns it.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
BleepingComputer · · International

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Ostium, a crypto trading platform, lost nearly $23.75 million after an attacker compromised the off-chain system responsible for supplying price data to its protocol, draining funds from its liquidity provider vault. The breach did not target the blockchain directly but exploited the infrastructure connecting external data to the on-chain system.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
The Record · · International

India says allegedly leaked nuclear plant files pose no safety risk

Indian officials responded to claims by the cybercrime group World Leaks that it had leaked files from the Kudankulam Nuclear Power Plant, stating that the documents do not contain safety or security-relevant information. The government has not denied that a leak occurred, only that the content is not sensitive.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Record · · International

Hackers were inside South Korea's diplomat training system for 9 months

Unidentified hackers spent roughly nine months inside an online training system used by South Korea's diplomatic academy, extracting personal data belonging to current and former employees of the Ministry of Foreign Affairs. The breach was not detected for the duration of that access.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →