Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
feld (feld@bikeshed.party)'s status on Thursday, 04-Jan-2024 02:59:59 JST feld
@jomo @lorenzofb agreed, it was a credential stuffing attack. no 2FA and they just used a giant list of emails and passwords and logged into any account they could. 23&Me should have had some rate limiting and alerts for this, but c'est la vie, right?
maybe customers shouldn't reuse passwords or something idk