23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

A coalition of 42 state attorneys general has agreed to a $18 million settlement with 23andMe (now Chrome Holding Co.) to resolve alleged cybersecurity failures that led to an October 2023 data breach affecting 6.9 million of its customers. The settlement also includes a commitment to implement new data security measures to better secure consumer data and prevent further data breaches.

The 23andMe data breach occurred as a result of credential stuffing, which is where credentials obtained in a data breach at one or more companies are used to try to gain access to accounts on an unrelated platform. These attacks can only succeed if individuals reuse the same credentials across multiple accounts. When the credential stuffing campaign was discovered, 23andMe maintained that there had not been a breach, and that the compromised accounts were the result of customers’ poor security practices.

While 23andMe customers took risks by reusing their credentials on the 23andMe site, the multistate investigation found that 23andMe was at fault as the company lacked basic cybersecurity measures for preventing credential-based attacks. For instance, 23andMe did not compare users’ passwords against blocklists of known breached passwords, did not require multifactor authentication, and did not have rate limiting or intrusion prevention measures in place. Further, there was insufficient logging and monitoring, which allowed the credential-stuffing campaign to go unnoticed for five months between April 2023 and September 2023, and a failure to investigate and address unusual login patterns, such as a massive spike in login attempts indicative of a credential stuffing campaign. The investigation also identified a failure to fix known vulnerabilities and properly review and test design features of its platform.

23andMe filed for bankruptcy protection in March 2025, and the company’s data was sold to TTAM Research, a company formed by 23andMe founder and former CEO, Anne Wojcicki. The coalition sued 23andMe during the company’s bankruptcy, and the new data security requirements apply to TTAM, which is now registered as 23andMe Research Institute. The $18 million settlement will be paid to the participating states, with New York due to receive more than $705,000.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” said Attorney General James. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law, and strict rules will be put in place to protect their customers.”

23andMe has previously agreed to pay $46.75 million as compensation to victims of the data breach, and has previously been fined by data protection watchdogs in Spain ($2.75M) and the United Kingdom ($3.1M) over the data breach. California did not participate in the multistate action, having filed its own lawsuit; however, a bankruptcy judge ruled this month that the state cannot seek monetary relief due to its Chapter 11 reorganization plan.

The post 23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit appeared first on The HIPAA Journal.

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy Exact Sciences systems of its cancer diagnostics business, and another involving its LabCentral portal.

Abbott acquired Exact Sciences in late 2025, a company specializing in cancer screening and precision oncology diagnostics. The acquisition allowed the company to enter the fast-growing cancer diagnostics market. Abbott has yet to confirm the extent to which patient data has been compromised but has confirmed unauthorized access to certain legacy cancer diagnostics systems. The intrusion did not impact any other Abbott businesses, and had no impact on its business operations, products, product availability, manufacturing/lab operations, or its ability to serve patients. The impacted Exact Sciences systems are separate from Abbott’s systems. In a July 16, 2026, announcement, Abbott said it does not anticipate the incident having any material impact on the business or its financial results.

The ShinyHunters data theft and extortion group claimed responsibility for the attack and threatened to publish the stolen data if payment was not made. Abbott negotiated with the group, and the publication deadline was extended to July 21, 2026. It is currently unclear if payment has been made, and as of July 20, 2026, the stolen data has not been leaked.

ShinyHunters often compromises victims’ systems through voice phishing (vishing) and appears to have used those tactics in this attack. Bleeping Computer reports that it received communications from a ShinyHunters spokesperson stating vishing attacks were conducted on Abbott employees in mid-June, which allowed the group to compromise a Microsoft Entra single sign-on account that provided access to certain internal systems. The group claims to have exfiltrated 30 million rows of customer data, including names, contact information, dates of birth, and one million Social Security numbers.

An investigation has also been launched into a separate claim from a hacker with the moniker ShadowByt3$. This separate attack, so the hacker claims, involved unauthorized access to the Abbott core business via the LabCentral customer portal. The threat actor claims to have gained access on July 4, 2026, using compromised customer credentials, exfiltrating data over the weekend, although no customer or patient data was compromised. Abbott maintains that the third-party hosted portal does not contain sensitive data, only publicly available, non-sensitive data, such as technical product reference documents including operating manuals, product specifications, and troubleshooting checklists.

Abbott is one of several medtech companies to announce cyberattacks and data breaches in recent months, including Stryker, Medtronic, iRhythm, AdaptHealth, and Intuitive.

The post Abbott Investigating Cyberattack Claims From Two Threat Actors appeared first on The HIPAA Journal.

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a Hanover, New Jersey-based diagnostic testing laboratory that provides medical and diagnostic testing services to healthcare providers, has announced an August 2025 cybersecurity incident affecting more than half a million patients of its healthcare provider clients.

Suspicious activity was identified within its computer systems on August 25, 2025. Systems were isolated to contain the incident, and steps were taken to prevent further unauthorized access. The forensic investigation confirmed that an unauthorized third party gained limited access to certain systems between August 9, 2025, and August 14, 2025. The forensic investigators determined that files containing patient data were exfiltrated from its systems by an unauthorized third party.

Centers Lab engaged third-party data review specialists to perform a detailed review of the impacted data, and after that process was completed, the findings were internally validated. The validation process has recently been completed, and notification letters have been mailed to the affected individuals.  The information compromised in the incident varies from individual to individual and may include names in combination with some or all of the following: date of birth, Social Security number, passport number, driver’s license number/state ID number, medical information, and health insurance information.

Centers Lab said additional data security measures have been implemented to prevent similar incidents in the future, stressing that strong cybersecurity measures had already been implemented prior to the incident. As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring and identity theft protection services for between 12 and 24 months. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 542,377 individuals.

While not disclosed by Centers Lab, the Worldleaks threat group claimed responsibility for the attack and published the stolen data on its dark web data leak site. The affected individuals should therefore take advantage of the free services being offered as a precaution against data misuse.

The post Centers Laboratory Discloses Data Breach Affecting 542K Individuals appeared first on The HIPAA Journal.