Does this mean that 2FA was not in place? For a company handling such personal information, this seems like a minimum requirement.
> After disclosing the breach, 23andMe reset all customer passwords, and then required all customers to use multi-factor authentication, which was only optional before the breach.
Add in all the people who struggle to use 2FA of any kind. At my first employer, I was there when they implemented it and it basically destroyed an entire week of productivity as so many people struggled to grasp how to set up a token in the authenticator app and use the token. I would be curious to know what the stats are on how 2FA impacts use and churn of users.
Ultimately, companies like this are making the choice of information safety vs profits - it’s a tale as old as the free market.