Hackers posted a 23andMe data sample on BreachForums, claiming 1M data points exclusively on Ashkenazi Jews, but the sample appears to lack raw genetic data
At least a million data points from 23andMe accounts appear to have been exposed on BreachForums.
WiredLily Hay Newman
Context & Ripple Effects
This was an early public signal in the 23andMe incident: an alleged dataset was posted publicly, while the available sample did not establish that raw genetic files were included. The claimed focus on Ashkenazi Jewish accounts made the exposure especially sensitive even before its scope was clear.
23andMe had to determine whether the forum material was authentic, what account and ancestry information it contained, and whether affected users faced targeted privacy or harassment risks.
The absence of apparent raw genetic data narrowed one category of exposure, but did not eliminate the sensitivity of account and ancestry information attributed to a specific population.
Second-order effects
The later expansion from a sample to a claimed larger dataset increased pressure on 23andMe to communicate scope and containment as public leak claims evolved.
The eventual report that ancestry data affecting 6.9M customers was stolen through access to roughly 14,000 accounts connected account security to much wider family-data exposure, raising the stakes for safeguards around account access and data-sharing features.
Third-order effects
If account-level compromises can expose ancestry information connected to many more people, consumer genetics services will be judged on protection of relationship-linked data, not only on protection of individual login credentials.
The episode points toward a more demanding privacy standard for consumer genetic databases, particularly where leaked metadata can enable targeting of identifiable communities.
The trend: Consumer genetic-data breaches are increasingly exposing the security consequences of ancestry networks, where a limited number of account takeovers can affect a far broader set of people.
DNA testing company 23andMe just confirmed a potential data breach: Threat actor used credentials exposed in other leaks to access legitimate 23andMe user accounts and scrape data, including “tailored ethnic groupings,” like 1 million lines of data on Ashkenazi people... https://…
Consumer DNA testing company 23andMe is investigating a potential data breach: — Threat actor used credentials exposed in other leaks to access legitimate 23andMe user accounts and scrape data, including “tailored ethnic groupings,” like 1 million lines of data on Ashkenazi peo…
23andMe user data was seemingly stolen in a credential stuffing campaign that targeted Ashkenazi Jews. Also maybe data from Mark Zuckerberg, Elon Musk and Sergey Brin is in the leak? 23andMe seems to be confirming the incident yet hasn't validated the data https://www.wired.com/…
Latest catastrophic data breach involves a company storing some of the most sensitive possible information about individuals. There will be no consequences apart from damaging those people's lives, of course — because there is no accountability for any of this. …
The compromised accounts had opted into the platform's ‘DNA Relatives’ feature. The hacker accessed a few 23andMe accounts and scraped the data of their DNA Relative matches, showing the potential risks of such features. [image]
TARGETED LEAK: The initial data leak was limited but deeply concerning. The threat actor released 1 million lines of data specifically for Ashkenazi people. This targeted attack raises serious questions about the motive behind the breach. [image]
When Ancestry and 23andMe data gets hacked more regularly (and for other reasons than the reason below), do not be surprised when law enforcement agencies start quietly purchasing that data.
I considered doing 23andMe several times, because members of my family who did got in contact with some distant Jewish relatives in Ukraine that way. But I ultimately never did it, because the thought of a private company having a database of genetic Jews seemed too scary.
23andMe user data was seemingly stolen in a credential stuffing campaign that targeted Ashkenazi Jews. Also maybe data from Mark Zuckerberg, Elon Musk and Sergey Brin is in the leak? 23andMe seems to be confirming the incident yet hasn't validated the data https://www.wired.com/.…
A security researcher told me he found his wife's information in the #23andMe files, which had 1 million users of Ashkenazi heritage and 300,000 users of Chinese heritage 23andMe first denied the leak then said it was due to scraping @TheRecord_Media https://therecord.media/...
“23andMe” says user data stolen. On October 4, the threat actor offered to sell data profiles in bulk for $1-$10 per 23andMe account, depending on how many were purchased. …