News: 1706284809

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Guess the company: Takes your DNA, blames you when criminals steal it, can’t spot a cyberattack for 5 months

(2024/01/26)


Biotech and DNA-collection biz 23andMe, the one that blamed its own customers for the October mega-breach, just admitted it failed to detect any malicious activity for the entire five months attackers were breaking into user accounts.

In a collection of data breach notifications [1]filed with California's attorney general Rob Bonta, 23andMe revealed attackers were using credential stuffing techniques between April 29 and September 27, 2023.

It also said the malicious activity was only [2]detected in October after seeing a Reddit post related to the sale of the data, rather than interal security tooling picking up on the mess.

[3]

It's not clear how many accounts were targeted over that five-month period, but the company previously said that [4]14,000 accounts were broken into , accounts that had the DNA Relatives feature enabled which ultimately exposed the data of 6.9 million individuals.

[5]

[6]

DNA Relatives is a core feature of the 23andMe service that allows users to find individuals they may be related to, based on how strong the DNA match is between them.

If an account was compromised through credential stuffing, the data shared by those with even a minuscule percentage of shared DNA could have been scooped up by the attacker.

[7]

23andMe's breach notifications laid out the type of data that could have been stolen. Basic profile information that was likely to have been exfiltrated in the event of a compromise included last login data, relationship labels (masculine, feminine, neutral), predicted relationships such as great aunt, percentage of DNA shared, and the account display name.

Display names are configurable on 23andMe, with a range of options available from full names to just the first initial of each name.

Optionally, users can also choose to share additional information with those who share their DNA, including ancestry reports, matching DNA segments (what chromosomes match), location, ancestor birth locations, family names, profile picture, birth year, family trees, and personal bios.

[8]

Credential stuffing attacks can in some cases be difficult for organizations to detect given the compromised accounts were accessed using the proper credentials, though there are various controls that can be implemented to help spot malicious activity.

Endpoint solutions can pick up on single sources trying to log into accounts en masse, for example, and that IP address can then be blocked, preventing further intrusion attempts.

But the main way to stop credential stuffing in its tracks is to just enable two-factor or multi-factor authentication, as has been the advice of the industry for god knows how long now.

23andMe only started mandating 2FA by default in November, a month after it detected the breach.

In letters sent to lawyers representing 23andMe breach victims, the biotech firm said the breach was caused by user negligence, denying all allegations that its alleged security failures were instead the leading cause.

The letter read: "As set forth in 23andMe's October 6, 2023 blog post, 23andMe believes that unauthorized actors managed to access certain user accounts in instances where users recycled their own login credentials – that is, users used the same usernames and passwords used on 23andMe.com as on other websites that had been subject to prior security breaches, and users negligently recycled and failed to update their passwords following these past security incidents, which are unrelated to 23andMe. Therefore, the incident was not a result of 23andMe's alleged failure to maintain reasonable security measures under the CPRA.

The leak of the "blame game" letter predictably prompted many in the infosec industry to [9]rally against 23andMe , citing the lack of 2/MFA at the heart of their criticisms of the stance.

[10]Infosec experts divided over 23andMe's 'victim-blaming' stance on data breach

[11]23andMe responds to breach with new suit-limiting user terms

[12]Cybercrim claims fresh 23andMe batch takes leaked records to 5 million

[13]DNAaaahahaha: Twins' 23andMe, Ancestry, etc genetic tests vary wildly, surprising no one

Others sided with the company, saying the users were indeed at fault for not changing their login credentials after they were compromised in a previous breach – a breach about which they were most likely alerted over email. One likened it to deliberately crashing a car into a tree and blaming the car manufacturer.

This all came after the company tried to limit victims' ability to launch legal action by changing its terms of service. It controversially introduced a new 60-day dispute resolution period that stipulated aggrieved customers must first attempt to resolve a dispute informally before pursuing their legal options.

23andMe did not immediately respond to a request for a statement. ®

Get our [14]Tech Resources



[1] https://oag.ca.gov/ecrime/databreach/reports/sb24-579679

[2] https://www.theregister.com/2023/10/19/latest_23andme_data_leak_takes/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbPlPLKKzWZPVXzUFf9xjwAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2023/12/11/in_brief_security/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbPlPLKKzWZPVXzUFf9xjwAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbPlPLKKzWZPVXzUFf9xjwAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbPlPLKKzWZPVXzUFf9xjwAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbPlPLKKzWZPVXzUFf9xjwAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2024/01/04/23andme_victim_blaming_breach/

[10] https://www.theregister.com/2024/01/04/23andme_victim_blaming_breach/

[11] https://www.theregister.com/2023/12/11/in_brief_security/

[12] https://www.theregister.com/2023/10/19/latest_23andme_data_leak_takes/

[13] https://www.theregister.com/2019/01/18/dna_twins_gene_tests/

[14] https://whitepapers.theregister.com/



Reddit??

Anonymous Coward

Hold on, you're a cybercriminal who's just stolen a load of data, and instead of going to some Tor-embedded Dark Web site, you advertise it for sale on Reddit, a site which can be assumed to cooperate with authorities? Even if *you've* managed to sign up to Reddit using a completely untrackable email address and always browse via Tor with no exception, Reddit admins should still have no trouble tracking who reads and interacts with your post before they take it down.

Re: Reddit??

TimMaher

The article doesn’t say it was for sale on Reddit, it was referenced.

Probably some typical Reddit user has also used 23 and had a previously compromised credential, that they continued to use,

Seems to fit the bill.

I got a good idea!

Omnipresent

Let's all send our DNA to the internet! It's brilliant. Nobody will care, they are not after you anyway.

Also, don't worry about that twitter/russia connection.

Doctor Syntax

Let me guess: they use the email address as userID. This would almost invariably be the same email address their customers use on many other sites so as soon as one of those sites is compromised the full login credentials become available. While 23andme - and any other company - can't stop their customers reusing passwords* they can stop them reusing login IDs by the simple expedient of issuing their own, non-email, IDs. There's no need to go to 2FA. The only reason that that's industry standard is because email as userID is also industry standard.

* Actually there is something they can do. They can check any ID/password combination they find against haveibeenpwned, reject them and advise their customers to reeset all their other passwords. They could also monitor haveibeenpwned for additions which match their own customers' credentials and force a password reset on any that match.

Anyway, I keep picturing all these little kids playing some game in this
big field of rye and all. Thousands of little kids, and nobody's around --
nobody big, I mean -- except me. And I'm standing on the edge of some crazy
cliff. What I have to do, I have to catch everybody if they start to go
over the cliff -- I mean if they're running and they don't look where they're
going I have to come out from somewhere and catch them. That's all I'd do
all day. I'd just be the catcher in the rye. I know it; I know it's crazy,
but that's the only thing I'd really like to be. I know it's crazy.
-- J. D. Salinger, "Catcher in the Rye"