Genetic testing company 23andMe has agreed to an $18 million settlement with 43 state attorneys general over failure to protect customer genetic data.
The settlement resolves allegations that 23andMe inadequately safeguarded sensitive genetic information. The company failed to implement reasonable security measures, leaving customer DNA profiles and ancestry data vulnerable to unauthorized access.
The breach exposed millions of users' genetic information, raising concerns about privacy and data protection in the biotech industry. Regulators argued the company did not adequately warn customers about security risks or obtain proper consent for data handling practices.
23andMe operates one of the largest consumer genetic databases globally. The company has faced increasing scrutiny over data privacy practices as genetic testing becomes more mainstream. This settlement marks one of the largest penalties against a direct-to-consumer genetics company.
The $18 million will be distributed among the states involved in the settlement. Additionally, 23andMe agreed to strengthen its security protocols and implement enhanced data protection measures going forward.
Norway is considering regulatory measures against camera-enabled wearable headsets, citing serious privacy concerns. The Nordic country aims to address risks posed by devices capable of covert recording.
Dropbox is notifying users of unauthorized account access resulting from an email verification vulnerability in Lenovo's identity system. Attackers exploited the flaw to create fraudulent Lenovo IDs and gain entry to Dropbox accounts.
A California federal grand jury has indicted a Russian national for orchestrating a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
The FBI is investigating a newly launched dark web service called Nexus that claims to possess digital scans of over 153 million driver's licenses from US and Canadian residents. The service is actively selling the stolen identification data.