3 ms·
23andMe is trying to have us believe that multiple tens of thousands of their customers were hacked in a credential stuffing attack. With 1500 matches per perso
by mikenuts 3y ago
23andMe is trying to have us believe that multiple tens of thousands of their customers were hacked in a credential stuffing attack. With 1500 matches per person, assuming no overlapping relatives, you'd need somewhere around 10,000 successfully hacked accounts to get the amount of data they have (~14 million). In reality, many people have overlapping relatives with other people, so many more than 10,000 accounts would have needed to be attacked, all without 23andMe noticing anything suspicious. This seems very unlikely to me.
And while 23andMe claims that a credential stuffing attack was at the root cause of this leak, the hacker(s) who first posted about this leak on Hydra Market over 2 months ago claim that they simply used (abused?) an API that 23andMe offered to their academic and research collaborators.
The hacker(s) claimed to have 300TB of data, including raw data, but have not proven that the scope of the attack was that large. But if their claim is true, then the breach was definitely not due to a credential stuffing attack, but fits well with the hacker(s) claim of using an API.
So, if the extent is as claimed by the attacker(s), then it is much more likely that one of 23andMe's API was used to scrape everyone's data, not a credential stuffing attack. Either one of their collaborating researchers got hacked, or they had (have!?) an access control vulnerability in their API which allowed the attacker to again scrape everyone's data.
I cannot find much information about the API 23andMe offers, but I did find one on RapidAPI (https://rapidapi.com/23andme/api/23andme https://rapidapi.com/23andme/api/23andme), and indeed if there was some sort of access control vulnerability or some sort of hack of an escalated user then with even 1 individual as a starting point, they could download the data using various endpoints (there's even an endpoint for the entire individual's genome...) and then get the relatives of that individual (an endpoint for that too) and then recursively do the same for all relatives until every person has been downloaded once.
At this point in time, I am highly suspicious of 23andMe's defense but until the attacker releases proof that they have raw data we can't really prove that they're wrong/lying about the actual magnitude of the attack. But I do believe their claim of using an API makes a lot more sense than the way 23andMe proposed, so I am very worried.
- gosub100 3y ago> and then get the relatives of that individual so you're saying they used a genetic algorithm ? sorry, couldn't resist.