Threat Intelligence Brief
Curated summary with source attribution
Source: doj.nh.gov
Threat Risk: Medium
Victim: Genetic testing consumers
Incident: A large-scale data breach involving the theft of genetic ancestry data via credential stuffing.
Impact: Sensitive genetic data of 6.9 million customers was compromised and sold on the dark web.
Attacker: Unidentified threat actors
Analysis: The breach was primarily driven by a failure to implement fundamental authentication controls, such as multi-factor authentication and rate limiting. Attackers successfully utilized credential stuffing to bypass security and access millions of accounts. The delayed detection and initial denial of the event underscore a critical lack of effective logging and monitoring.
Recommendations: Enforce mandatory multi-factor authentication (MFA) for all user accounts.; Implement robust rate limiting and account lockout policies to thwart automated credential stuffing.; Integrate password blocklists to prevent users from utilizing known compromised credentials.
Source: New Hampshire Department of Justice
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source