Victims of the 23andme data breach receive millions in compensation
Ein US-Gericht hat beschlossen, dass die Opfer eines Datenlecks bei 23andme eine Entschädigung in Höhe von 46,75 Millionen US-Dollar erhalten. Allerdings wird Chrome Holding, die neue Eigentümerin von 23andme, nur 32,46 Millionen US-Dollar zahlen müssen, da 14,29 Millionen US-Dollar bereits vorher gezahlt wurden. Das Datenleck aus dem Jahr 2023 ermöglichte Kriminellen, vier Millionen Datensätze zu stehlen, darunter persönliche und genetische Informationen. 23andme wies die Verantwortung zunächst auf die sogenannte 'Credential Stuffing'-Methode zurück, wonach die Zugangsdaten außerhalb des Unternehmens gestohlen wurden. Das Unternehmen ging daraufhin in Insolvenz, was zu einem starken Rückgang des Aktienkurses führte. Die neue Eigentümerin, Chrome Holding, ist mit der Gründerin Anne Wojcicki verbunden. Zuletzt wurde ein neues Verfahren eingeleitet, in dem der kalifornische Generalstaatsanwalt vorgeworfen wird, 23andme für mangelnde Sicherheitsmaßnahmen und unzureichende Informationsschulung verantwortlich gemacht zu haben.
A U.S. bankruptcy court has approved a settlement requiring the owner of the genetic testing company 23andme to pay $46.75 million in compensation to victims of a major data breach. The ruling was made by Judge Brian Walsh of the U.S. Bankruptcy Court in St. Louis, Missouri. However, the final amount to be paid will be reduced due to prior payments already made to affected users. According to reports, the entity responsible for compensating victims, Chrome Holding, will ultimately pay $32.46 million after subtracting $14.29 million previously distributed as part of earlier settlements related to the breach. The data breach occurred in 2023 when over four million customer records were copied by cybercriminals and put up for sale on dark web marketplaces. These records included names, addresses, birth years, genomic information, and access to profiles of individuals whose relatives had been shared within the platform. This exposure raised serious concerns about privacy and security among users who had entrusted their sensitive personal and genetic data to the company. At the time of the breach, 23andme denied responsibility, arguing that users were at fault for using weak passwords or reusing login credentials from other platforms where they might have been compromised. The company attributed the breach to credential stuffing, a method in which attackers use stolen usernames and passwords from one service to gain unauthorized access to another. In this case, 23andme claimed that users had used the same credentials elsewhere, allowing hackers to exploit these vulnerabilities and gain entry into their system. Founded in 2006 by Anne Wojcicki, later wife of Google co-founder Sergey Brin, along with Linda Avey and Paul Cusenza, 23andme provides genetic analysis services, including insights into disease predispositions, traits, and ancestry. Following the data breach, the company experienced a significant decline in value, with its stock price dropping by 75 percent in 2024 before filing for bankruptcy. As a result, the company's assets were auctioned off, and Chrome Holding, operating under the name TTAM Research Institute, won the bid for $305 million. Behind TTAM Research Institute is Wojcicki, one of the founding figures of 23andme. Recently, new legal proceedings have been initiated against 23andme regarding the data breach. California Attorney General Rob Bonta has accused the company of failing to detect suspicious activities on its servers, neglecting to implement robust data protection measures, and inadequately informing the public about the incident. These allegations suggest that the company did not take sufficient steps to prevent the breach or adequately warn users of the risks associated with their data being exposed. The outcome of the current legal actions could influence how future data breaches are handled, particularly concerning corporate accountability and user notification practices. With the settlement now in place, affected users will receive financial compensation, though the exact distribution process remains unclear. Meanwhile, the ongoing legal challenges highlight the broader issues surrounding data security and the responsibilities of companies handling sensitive personal information. As the situation develops, further details about the compensation plan and the legal implications for both 23andme and its new owners will likely emerge. The case also underscores the growing importance of cybersecurity in the digital age, especially for companies dealing with highly sensitive data such as genetic information. The resolution of this matter may set important precedents for similar cases involving data breaches and corporate liability.
How each side covered it
The same event, grouped by the political lean of the outlets covering it.
progressive
center
conservative
★
How each side covered it
Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.
Ein US-Gericht hat beschlossen, dass die Opfer eines Datenlecks bei 23andme eine Entschädigung in Höhe von 46,75 Millionen US-Dollar erhalten. Allerdings wird Chrome Holding, die neue Eigentümerin von 23andme, nur 32,46 Millionen US-Dollar zahlen müssen, da 14,29 Millionen US-Dollar bereits vorher gezahlt wurden. Das Datenleck aus dem Jahr 2023 ermöglichte Kriminellen, vier Millionen Datensätze zu stehlen, darunter persönliche und genetische Informationen. 23andme wies die Verantwortung zunächst auf die sogenannte 'Credential Stuffing'-Methode zurück, wonach die Zugangsdaten außerhalb des Unternehmens gestohlen wurden. Das Unternehmen ging daraufhin in Insolvenz, was zu einem starken Rückgang des Aktienkurses führte. Die neue Eigentümerin, Chrome Holding, ist mit der Gründerin Anne Wojcicki verbunden. Zuletzt wurde ein neues Verfahren eingeleitet, in dem der kalifornische Generalstaatsanwalt vorgeworfen wird, 23andme für mangelnde Sicherheitsmaßnahmen und unzureichende Informationsschulung verantwortlich gemacht zu haben.
Bias read (Center): Die Berichterstattung bleibt sachlich und präsentiert Fakten ohne klare politische Einordnung. Es wird keine starke emotionale oder ideologische Ausrichtung erkennbar, sondern lediglich die rechtlichen und finanziellen Konsequenzen des Datenlecks dargestellt. Die Quellen werden neutral zitiert, und淟
Why these scores (Factual 85 · Objective 65): Factually accurate, aligns with the primary source document regarding the payout and breach details. However, it presents a more subjective narrative by emphasizing 23andMe's defense of 'Credential Stuffing' and blaming users, which introduces bias. The article also omits some key details like the I
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.