Don’t do SECURITY. Do business SECURELY.

23andMe user data stolen after credential stuffing attack

Hackers used reused passwords to access 23andMe accounts and scraped ancestry data on about 6.9 million people.

Genetic testing company 23andMe confirmed that data on its users had been stolen and advertised for sale online. It later said hackers had accessed about 14,000 accounts, which gave them access to ancestry data on around 6.9 million people.

What happened

  • Attackers used credential stuffing, logging in with usernames and passwords leaked from other sites.
  • Through the DNA Relatives feature, each compromised account exposed information about many other users.
  • Exposed data included names, relationship labels, and ancestry reports; early leaks were reported to have targeted people of Ashkenazi Jewish and Chinese descent.
  • The company faced lawsuits and was later fined by the UK ICO.

Why it mattered

The breach showed how account features that share data between users can multiply the impact of a small number of compromised accounts, particularly for sensitive genetic data. 23andMe later drew criticism for telling affected users that their own password reuse was to blame.

Lessons for organisations

Organisations should enforce multi-factor authentication, detect credential stuffing, and consider how data-sharing features increase the impact if an account is compromised. Special category data such as genetic information calls for stronger protection under UK GDPR.

Sources: TechCrunch, Axios

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights