PrivacySignal
Breach

23andMe to pay $18 million in new genetics data breach settlement

BleepingComputer · · International · Data Breaches

23andMe has agreed to an $18 million settlement with a coalition of 43 state attorneys general over its failure to adequately protect customers' genetic data from a breach. The settlement resolves multistate claims that the company did not take sufficient steps to secure some of the most sensitive personal information people can share.

Why this matters: Genetic data is not like a leaked password. You can change a password. You cannot change your DNA, and neither can your relatives, who never agreed to be in 23andMe's database in the first place. A breach here is permanent exposure. Eighteen million dollars sounds large, but spread across millions of affected customers it is a rounding error. The real accountability question is whether this settlement actually changes how companies handle biological data, or whether it just prices the risk of getting caught.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

A large cache of internal Valve data, reportedly totaling 12 terabytes, has leaked from an unknown source and is being analyzed online. The files appear to include unreleased beta builds of several classic Valve games and possible content from the long-cancelled Half-Life 2: Episode 3.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

VT: Local VA warns of possible data breach

The VA's White River Junction, Vermont healthcare facility disclosed that unencrypted communications containing veterans' personal health information were sent in error earlier this summer. The department acknowledged the incident in a public release, confirming the exposure was unintentional.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →
Breach
DataBreaches.net · · International

De: Hackers demand 30 bitcoin from Berlin as sensitive data breach widens

Hackers have demanded 30 bitcoin from the Berlin city government following a breach of its administrative data network, with the attack occurring roughly two weeks ago. Berlin officials are declining to disclose what data was accessed, who is responsible, or how they are responding to the ransom demand.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance

#breach#gdpr Read original →
Breach
DataBreaches.net · · International

US officials backpedal on claims that government agencies were hacked by Chinese

U.S. officials have walked back earlier statements claiming Chinese spies successfully hacked several government agencies, clarifying that the Senate, the Federal Reserve, NASA, and others were targeted but not confirmed as breached. The Justice Department quietly updated its language to reflect the distinction.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

PEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silent

SuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim is South Plains Rural Health Services, Inc. (SPRHS), a nonprofit healthcare organization that has provided services to rural communities across West Texas for decades. The information... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Two different groups have recently attacked Interim HealthCare entities. Should other franchises be concerned?

Two separate threat actors have attacked different Interim HealthCare franchise locations, with breaches at the West Texas and Amarillo franchises affecting nearly 2,800 patients combined and triggering federal notifications to the Department of Health and Human Services.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →