[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flycZZ_OURME8MT0BdSVVEPwwWuZI8bA6_rmhPCGlzm4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"b3705efb-1357-4f6d-8df2-6c735a9e8fca","23andme-breach-multi-factor-authentication-and-incident-response-failures","598b8826-7d48-45b1-aac2-c067627d9259","23andMe Breach: Multi-Factor Authentication and Incident Response Failures","23andMe suffered a massive breach affecting 7 million users through credential-stuffing attacks, where attackers used previously compromised passwords to access accounts. The company failed to implement basic security controls like mandatory multi-factor authentication (MFA) despite knowing about similar attacks on genetic testing companies since 2017. Most critically, 23andMe delayed investigating the breach for five months until stolen data appeared on the dark web, demonstrating poor incident response capabilities. This case highlights how inadequate access controls and delayed incident response can amplify the impact of data breaches, especially for sensitive genetic information.","**Immediate actions:**\n- Enable mandatory multi-factor authentication for all user accounts\n- Force password resets for accounts with weak or potentially compromised credentials\n- Implement real-time monitoring for credential-stuffing attack patterns\n\n**Long-term improvements:**\n- Establish automated incident response procedures with defined investigation timelines\n- Deploy advanced authentication controls like risk-based authentication and CAPTCHA\n- Create comprehensive data breach response plans with regulatory notification requirements\n\n**Detection measures:**\n- Monitor for unusual login patterns and multiple failed authentication attempts\n- Set up alerts for account access from new devices or geographic locations\n- Implement dark web monitoring to detect if customer data appears in underground markets",[12,13,14,15,16,17],"CIS Control 6 (Access Control Management)","CIS Control 17 (Incident Response Management)","NIST AC-2 (Account Management)","NIST IR-4 (Incident Handling)","GDPR Article 32 (Security of Processing)","GDPR Article 33 (Notification of Breach)","published","2026-05-29T12:20:33.636822+00:00","2026-05-29T12:20:33.534+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Fcalifornia-sues-23andme-alleging-it-failed-to-protect-user-data-in-2023-breach\u002F","california-sues-23andme-alleging-it-failed-to-protect-user-data-in-2023-breach-5216b6","California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"ce05efbb-2503-4c8a-af78-9a84a3a8af9b","2026-05-29","afternoon","ThreatNoir Afternoon Brief — May 29","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-05-29\u002Fthreatnoir-afternoon-brief-2026-05-29.mp3"]