Introduction

The public biotechnology and genomics firm, 23andMe, confirmed on their website on October 6, 2023, that certain 23andMe customer profile information was circulating on hacker forms. The information that has been exposed from this incident includes full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location. As a result, 23andMe have notified their customers, and have pushed for them to reset their passwords and enable multi-factor authentication (MFA).

How the attack happened

The hackers used credential stuffing to gain access to a set of user accounts on 23andMe. Credential stuffing is a type of cyber attack in which a hacker uses stolen usernames and passwords (obtained from another breach or purchased off the dark web) to access other websites in which the users are registered. Users that recycled their breached login credentials on 23andMe may have been the entry point for this attack.  

A subset of the compromised users opted into 23andMe’s DNA Relatives feature, which allowed for hackers to scrape the data of their DNA Relative matches.  

The number of accounts affected has not been released or disclosed by 23andMe.

If you think you may have been affected by this recent breach, reset your password, and opt for MFA on 23andMe. While the account may or may not be compromised, it is important that cybercriminals do not leverage your breached credentials to access other websites in which you may have an account on.  

How to stay safe

  1. Reset All Passwords – If you have the bad habit of reusing passwords across different websites, reset those passwords and employ hard-to-guess, complex passwords on those websites.  
  2. Password Manager – To keep track of your complicated passwords, think about investing in a password manager. Password managers, like 1Password, place a secret key on your password manager to add a unique extra layer of security.  

Richter Guardian can help you determine if some of your user accounts were involved in a previous breach. Our platform can determine compromised credentials through comprehensive dark web monitoring.

Sources

  1. “Addressing Data Security Concerns”. 23andMe. 2023 October 6. Retrieved 10 October 2023.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Security advisories
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Article illustration: PetSmart Credential Stuffing Attack

PetSmart Warns Customers of Credential Stuffing Attack

PetSmart warned of a credential stuffing attack and reset some passwords. We explain what credential stuffing is and how to protect yourself with unique passwords, MFA, and dark web monitoring.

Introduction​

​PetSmart, a pet retail giant in the United States, is alerting certain customers about password resets resulting from an ongoing credential stuffing attack attempting to breach existing accounts. The company released a statement on March 6 to let customers know about the credential stuffing attack. ​

As a precaution, PetSmart reset the passwords for any accounts logged in during the credential stuffing attack. Additionally, they reassured customers that there was no evidence of compromise to petsmart.com or any of their systems during the incident.​

What is credential stuffing?

​A credential stuffing attack is a type of cyber-attack in which threat actors use previously acquired usernames and passwords, typically obtained from data breaches, to gain unauthorized access to user accounts on various online platforms. ​

Threat actors usually automate the process of trying these login credentials across multiple websites and services. Threat actors are cognizant of the fact that people commonly reuse passwords across various accounts, making them even more inclined to exploit this widespread behavior.

How to protect yourself against credential stuffing attacks

Although cyber breaches may be unavoidable, you can still prevent breached details from being used on other websites or services by taking the following precautions:

  1. Use Unique Passwords For Each Account – Minimize the impact if one account is compromised.​
  2. Enable Multi-Factor Authentication (MFA) – Implement MFA wherever possible to add an additional layer of security.​
  3. Update Outdated Passwords – Change your passwords periodically, especially for critical accounts like email, banking, and social media.​
  4. Limit Access – Only use trusted devices and networks to access sensitive accounts. Avoid logging in from public computers or unsecured Wi-Fi networks to access sensitive accounts. Ensure that you are not saving your credentials on a public computer.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: Synthetic and traditional identity theft scams

Navigating the terrain of synthetic and traditional theft scams

Synthetic and traditional identity theft both put your finances and reputation at risk. We share practical steps: credit monitoring, securing mail and documents, password vaults, and limiting what you carry.

Introduction​

In an increasingly interconnected digital world, safeguarding personal and financial information has never been more crucial. Cybercriminals can exploit stolen identity information to commit financial fraud, gain unauthorized access to accounts, and engage in other criminal activities. In the context of identity theft – there is both synthetic identity theft and traditional identity theft. ​

Synthetic identity theft combines personally identifiable information (PII) to manufacture a person or entity for the use of illegal, nefarious activity. ​

Traditional identity theft involves stealing an individual’s existing personal data to impersonate them. ​

Alternatively, synthetic identity theft involves criminals obtaining small fragments of a real person’s identity to fabricate a completely new identity. The real elements of the fabricated individual adds a sense of legitimacy to the identity. ​

Preventing identity theft of all kinds​

​Protecting yourself from identity theft, fraud, and unauthorized access to your sensitive data is our responsibility. Below, we have compiled a comprehensive list of security measures and best practices to help you fortify your defenses against potential threats. ​

By following these guidelines, you can take proactive steps to enhance your security and financial well-being. From monitoring your credit report to secure document disposal, each suggestion in this list is designed to empower you with the knowledge and tools to protect your valuable information and minimize the risks associated with identity theft and fraud.​

  1. Monitor Your Credit Report: Regularly monitor your credit report to detect any unauthorized activity. If you come across information unrelated to you, contact the creditor and inquire about the account or inquiry.
  2. Limit What You Carry: Avoid carrying additional credit cards, birth certificates, SIN cards, or passports in your wallet or purse unless absolutely necessary. This precaution reduces the amount of information a potential thief could access if your wallet or purse gets lost.
  3. Secure Your Mailbox: Consider installing a mailbox with a lock at your residence to minimize the risk of mail theft.
  4. Securely Dispose: Never dispose of credit card receipts or personal information documents in a public trash container; use a shredder instead.
  5. Secure Your Purse or Wallet: Never leave your purse or wallet unattended, whether at work or in places like churches, restaurants, fitness clubs, parties, or shopping carts. Also, avoid leaving your purse or wallet visible in your car, even if the vehicle is locked.
  6. Limit Your Credit: Limit the number of credit cards you possess and cancel inactive accounts to simplify your financial security.
  7. Be Careful of What you Disclose: Do not disclose your credit card, bank, or Social Insurance information over the phone, even if you initiated the call, unless you can confidently verify the call’s legitimacy
  8. Secure Receipts: Securely store and shred credit, debit, and ATM card receipts before disposing of them.
  9. Scrutinize Your Bills: Scrutinize your utility and subscription bills regularly to confirm the accuracy of the charges.
  10. Do Not Write Down Your Passwords (except in a Password Vault): Memorize your passwords and personal identification numbers (PINs) to eliminate the need to write them down or use a password vault. Remain vigilant when entering your PIN to ensure no one is observing you.
  11. Secure Your Information: Maintain a comprehensive list of all your credit and bank accounts in a secure location, such as a password vault. This will facilitate quick communication with issuers if your cards go missing, including providing account numbers, expiration dates, and customer service and fraud department contact numbers.
  12. Shred Pre-approved Credit Offers: Before discarding pre-approved credit offers, credit card receipts, or phone bills, tear them into small pieces or cross-cut shred them to prevent potential identity theft. Thieves can use such offers to apply for credit cards in your name and redirect them to their address.
  13. Keep Your Credit Information Accurate: According to consumer reporting legislation, if you believe any entry on your credit report is incorrect or incomplete, you can notify a major credit reporting bureau, which will verify the information at no charge. Remember that they typically do not accept disputes from third parties unless accompanied by a notarized power of attorney authorizing a licensed attorney or a family member to represent you or if the power of attorney is unlimited and irrevocable.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: Authenticator Apps vs SMS for Login Security

Why Authenticator Apps Are Safer Than SMS for Login Security

Authenticator apps are more secure than SMS for two-factor authentication. We compare both methods, explain SIM swapping and interception risks, and recommend using an authenticator app for important accounts.

Introduction

One of the best ways to add extra security to your accounts is through Multi-Factor Authentication (MFA) – this means you need more than just a user ID and password to log in. We strongly recommend using MFA for your important accounts.

However, not all MFA methods are equally secure. Authenticator apps are a safer option than SMS authentication methods because they generate security codes directly on your device. SMS authentication codes, on the other hand, can be intercepted by hackers.

What is Multi-Factor Authentication and what is the benefit?

MFA adds an extra step to logging in. Instead of just entering a user ID and password, you must also provide another piece of information, like a code from an app or a text message. This extra step makes it much harder for hackers to break into your account, even if they steal your password.

MFA method #1: What is an authenticator application?

An authenticator app is a mobile app that generates security codes for logging in. These codes are called Time-Based One-Time Passwords (TOTP) and change every 30 to 60 seconds.

When you set up an authenticator app for an account, you scan a QR code or enter a secret key. This links the authenticator app to your account and allows it to generate matching codes.

To log in, you enter your username, password, and the current code displayed on your authenticator app. If the code matches the one your account server expects, you get access.

Some popular authenticator applications include:  

  • Google Authenticator
  • Microsoft Authenticator
  • Authy
  • Duo Mobile

MFA method #2: What is SMS authentication?

SMS authentication is when a security code is sent to your phone via text message. You enter this code along with your user ID and password to log in. These codes are One-Time Passwords (OTP) which are generated for one-time use. OTPs can last for a specified amount of time – users will need to generate a new OTP if they exceed the time limit.  

Sometimes, websites may also send security codes via email instead of SMS, but the process is the same.

Why authenticator applications are preferred over SMS authentication

Authenticator apps provide better security than SMS codes for several reasons:

  • Less chance of being hacked: Authenticator apps generate codes directly on your device, while SMS codes are sent over the internet and can be stolen.
  • No risk of SIM swapping: Hackers can trick your phone provider into transferring your number to a new SIM card, allowing them to receive your SMS codes.
  • No risk of interception: SMS codes can be stolen using man-in-the-middle attacks, where hackers eavesdrop on internet traffic.
  • Codes change frequently: Authenticator apps refresh their codes every 30 to 60 seconds, making them harder to steal and use.

How hackers can steal SMS codes

Here are two common ways cybercriminals can steal SMS codes:

  • Man-in-the-Middle Attacks – Hackers intercept your internet traffic when you connect to an unprotected Wi-Fi network (like public Wi-Fi at a coffee shop). This can let them steal SMS codes.
  • SIM Swapping – A hacker contacts your mobile provider pretending to be you and tricks them into activating a new SIM card with your phone number. Now, they receive all your text messages, including your security codes.

How to keep your accounts safe

  • Use an authenticator app instead of SMS authentication whenever possible.
  • Protect your phone with a strong PIN or password.
  • Avoid using public Wi-Fi when entering security codes.
  • Never share your security codes with anyone.
  • Be cautious of phishing scams that try to trick you into revealing your codes.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.