Get the latest tech news

23andMe Failed to Detect Account Intrusions for Months


Plus: North Korean hackers get into generative AI, a phone surveillance tool that can monitor billions of devices gets exposed, and ambient light sensors pose a new privacy risk.

These accounts then gave attackers access to information voluntarily shared by users in a social feature the company calls DNA Relatives. But a state-mandated filing in California about the incident reveals that the attackers started compromising customers’ accounts in April and continued through much of September without the company ever detecting suspicious activity—and that someone was trying to guess and brute-force users' passwords. New findings from 404 Media highlight a particularly insidious service, Patternz, that draws data from ads in hundreds of thousands of popular, mainstream apps to reportedly fuel a global surveillance dragnet.

Get the Android app

Or read this on Wired

Read more on:

Photo of months

months

Photo of account intrusions

account intrusions

Related news:

News photo

23andMe’s data breach: cyberattack was missed for months

News photo

23andMe admits hackers stole raw genotype data - and that cyberattack went undetected for months | Firm says it didn't realize customers were being hacked

News photo

23andMe's data hack went unnoticed for months