
23andMe data breach overview:
- Who: Plaintiff Alyson Hu filed a class action lawsuit against 23andMe Inc.
- Why: 23andMe allegedly failed to take adequate cybersecurity measures to protect customers’ sensitive information from cybercriminals, resulting in a data breach that may have affected nearly 7 million individuals.
- Where: The 23andMe class action lawsuit was filed in Illinois federal court.
Genetic testing company 23andMe Inc. faces another class action lawsuit following an Oct. 6 data breach.
Unauthorized actors reportedly accessed 23andMe accounts, including millions of customers’ sensitive Personal Identifiable Information (PII), such as their names, usernames, regional locations, birth years, profile pictures and ethnicities.
Plaintiff Alyson Hu, a 23andMe customer, filed the 23andMe data breach class action lawsuit Dec. 26. She previously received notice her PII had been compromised.
“Since the [23andMe data breach] occurred, several news sources have reported that threat actors listed mass amounts of the stolen data for sale on the dark web,” Hu alleges. “Defendant has failed to address these reports, failed to inform victims when and how the data breach occurred and has even failed to say whether the security threat is still a risk to customers.”
Plaintiff argues adequate cybersecurity measures could have prevented 23andMe data breach
23andMe offers customers personalized genetic reports that include ancestry composition, DNA relatives, genetic health predispositions, genetic traits and other individualized genetic information.
To register for 23andMe genetic testing, customers purchase a genetic testing kit and provide 23andMe with detailed information about themselves. 23andMe then collects further individualized genetic information from customers, including their saliva sample information.
However, 23andMe failed to adopt adequate cybersecurity measures to protect customers’ PII from unauthorized actors, Hu alleges.
Genetic testing companies are “treasure troves” of sensitive information and therefore valuable targets for cybercriminals, the 23andMe class action lawsuit claims.
The lawsuit also alleges 23andMe has not been forthcoming with information about the data breach and attempted to blame customers with “recycled login credentials.”
While the threat actors accessed a limited number of 23andMe accounts, Hu says the cybercriminals accessed the PII of nearly 7 million individuals through 23andMe’s DNA relatives feature.
As a result of the 23andMe data breach, customers like Hu face the risk of identity theft well into the future and must spend time and money to mitigate the damage.
The 23andMe class action lawsuit asserts claims for negligence and violation of the Illinois Genetic Information Privacy Act.
A separate consumer filed a 23andMe data breach class action lawsuit in October, shortly after 23andMe announced the breach.
Were you affected by the 23andMe data breach? Tell us about your experience in the comments.
Hu is represented by Katrina Carroll of Lynch Carpenter LLP and Jonathan M. Jagher, Michael E. Moskovitz and Nia-Imara Barberousse Binns of Freed Kanner London & Millen LLC.
The 23andMe data breach class action lawsuit is Alyson Hu v. 23andMe Inc., Case No. 1:23-cv-17079, in the U.S. District Court for the Northern District of Illinois.
Don’t Miss Out!
Check out our list of Class Action Lawsuits and Class Action Settlements you may qualify to join!
Read About More Class Action Lawsuits & Class Action Settlements:
77 thoughts on23andMe hit with another class action lawsuit over data breach
This sucks. I live in Illinois and now am at risk.
My personal information is now vulnerable. Can’t imagine who has it or where itis
Many family members plus myself are concerned.
I have a couple kits including my own that I manage . I am very concerned about the results of this breach.
Early user and extensive family tree info connected, shown; relative sharing; ran data through other medical sites. Add
I bought 7 kits for my family 4 of the kits are Jewish decent. I got the email about the breach . I’m so worried and concerned.