Genetic testing company 23andMe has agreed to an $18 million settlement with 43 state attorneys general over failure to protect customer genetic data.
The settlement resolves allegations that 23andMe inadequately safeguarded sensitive genetic information. The company failed to implement reasonable security measures, leaving customer DNA profiles and ancestry data vulnerable to unauthorized access.
The breach exposed millions of users' genetic information, raising concerns about privacy and data protection in the biotech industry. Regulators argued the company did not adequately warn customers about security risks or obtain proper consent for data handling practices.
23andMe operates one of the largest consumer genetic databases globally. The company has faced increasing scrutiny over data privacy practices as genetic testing becomes more mainstream. This settlement marks one of the largest penalties against a direct-to-consumer genetics company.
The $18 million will be distributed among the states involved in the settlement. Additionally, 23andMe agreed to strengthen its security protocols and implement enhanced data protection measures going forward.
A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.
A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.
A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.
Over 8,300 internet-facing Gitea instances remain unpatched against a critical vulnerability being actively exploited in remote code execution attacks, according to Shadowserver.