Genetic testing company 23andMe confirmed that data on its users had been stolen and advertised for sale online. It later said hackers had accessed about 14,000 accounts, which gave them access to ancestry data on around 6.9 million people.
What happened
- Attackers used credential stuffing, logging in with usernames and passwords leaked from other sites.
- Through the DNA Relatives feature, each compromised account exposed information about many other users.
- Exposed data included names, relationship labels, and ancestry reports; early leaks were reported to have targeted people of Ashkenazi Jewish and Chinese descent.
- The company faced lawsuits and was later fined by the UK ICO.
Why it mattered
The breach showed how account features that share data between users can multiply the impact of a small number of compromised accounts, particularly for sensitive genetic data. 23andMe later drew criticism for telling affected users that their own password reuse was to blame.
Lessons for organisations
Organisations should enforce multi-factor authentication, detect credential stuffing, and consider how data-sharing features increase the impact if an account is compromised. Special category data such as genetic information calls for stronger protection under UK GDPR.
Sources: TechCrunch, Axios
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.