PrivacySignal
Breach

23andMe to pay $18 million in new genetics data breach settlement

BleepingComputer · · International · Data Breaches

23andMe has agreed to an $18 million settlement with a coalition of 43 state attorneys general over its failure to adequately protect customers' genetic data from a breach. The settlement resolves multistate claims that the company did not take sufficient steps to secure some of the most sensitive personal information people can share.

Why this matters: Genetic data is not like a leaked password. You can change a password. You cannot change your DNA, and neither can your relatives, who never agreed to be in 23andMe's database in the first place. A breach here is permanent exposure. Eighteen million dollars sounds large, but spread across millions of affected customers it is a rounding error. The real accountability question is whether this settlement actually changes how companies handle biological data, or whether it just prices the risk of getting caught.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

Microsoft warns of TerminalFix attacks deploying reverse tunnels

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

A rough day at the extortion office and a botched attack on Blossom Health.

An apparent extortionist targeted Blossom Health, a US telehealth and psychiatry platform, by compromising either the platform itself or an individual provider's account and sending what appears to be a ransom demand. The incident came to light after a patient contacted DataBreaches directly to report it.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Time’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.

A ransomware group called Orova claims to have stolen more than 150,000 patient records from Cardiology Associates of Port Huron, a Michigan cardiology practice operating across nine locations. Journalists have reviewed the data, which reportedly contains personally identifiable and protected health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

A large cache of internal Valve data, reportedly totaling 12 terabytes, has leaked from an unknown source and is being analyzed online. The files appear to include unreleased beta builds of several classic Valve games and possible content from the long-cancelled Half-Life 2: Episode 3.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

VT: Local VA warns of possible data breach

The VA's White River Junction, Vermont healthcare facility disclosed that unencrypted communications containing veterans' personal health information were sent in error earlier this summer. The department acknowledged the incident in a public release, confirming the exposure was unintentional.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →