@lorenzofb hot take: they are not wrong. If what they said is true, 23AndMe was not hacked, customers decided not to use 2FA and then use a known password, and did allow to share data with other customers. This is the customers' fault.
23AndMe did however not use standard security practices such as enforcing MFA, and it's right to blame them for that.