23andMe confirms that it is aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack
23andMe has confirmed to BleepingComputer that it is aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack.
BleepingComputer Bill Toulas
Context & Ripple Effects
This confirmation is the first firm acknowledgement of a problem that quickly moved beyond an isolated forum post: a sample advertised as tied to Ashkenazi Jewish users had already surfaced days later, underscoring the sensitivity of ancestry-linked information.
Subsequent coverage clarified the asymmetry in the incident: access to a small share of accounts was used to expose ancestry information affecting far more people, culminating in 23andMe's report that ancestry data tied to 6.9 million customers had been taken.
First-order effects
- 23andMe must investigate exposed accounts and the data accessible through them, while affected customers face potential disclosure of profile and ancestry-linked information on hacker forums.
- The company’s attribution centers the immediate security failure on reused or compromised customer credentials rather than a claimed intrusion into its core systems.
Second-order effects
- The episode makes account-level safeguards—such as stronger login controls and monitoring—more consequential for consumer data platforms whose sharing features can reveal information about people beyond the compromised account holder.
- Public circulation of sensitive ancestry-related records raises the reputational and privacy cost for genetic-testing customers and puts pressure on 23andMe to explain the reach of account connections and data-sharing settings.
Third-order effects
- If account compromise can propagate through family or ancestry networks, consumer genetic-data services will be judged not only on breach prevention but on whether their consent and sharing design limits downstream exposure.
- The case points toward a broader reassessment of how platforms protect highly sensitive data when identity security depends partly on users’ password practices.
The trend: Credential-stuffing incidents are becoming a test of whether platforms’ data-sharing architecture can contain harm after a single user account is compromised.
Related: 23andMe · Consent architecture · 23andMe investigates possible 4M-user data leak · 23andMe says ancestry data of 6.9M customers was stolen
Related Coverage
- 23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews Wired · Lily Hay Newman
- 23andMe scraping incident leaked data on 1.3 million users of Ashkenazi and Chinese descent The Record · Jonathan Greig
- 23andMe says private user data is up for sale after being scraped Ars Technica · Dan Goodin
- Genetic tester 23andMe's hacked data on Jewish users offered for sale online Washington Post · Joseph Menn
- Hacker Puts 23andMe User Data Up for Sale on the Internet Bloomberg · Margi Murphy
- DNA testing service 23andMe investigating theft of user data CyberScoop · AJ Vicens
- 23andMe User Accounts Exposed - Change Your Password Now DNAeXplained · Roberta Estes
- 23andMe Cyberbreach Exposes DNA Data, Potential Family Ties Dark Reading
- 23andMe user data breached in credential-stuffing attack Engadget · Malak Saleh
- 23andMe user data compromised in a “credential stuffing attack” Techaeris · Alex Hernandez
- 23andMe Warns of Hacker Breaking Into User Accounts PCMag · Michael Kan
- Genetics Firm 23andMe Confirms User Data, Including Results, Has Leaked Pixel Envy · Nick Heer
- 23andMe Accounts Hijacked and Data Put Up for Sale on Hacker Forum RestorePrivacy · Heinrich Long
- DNA Testing Company 23andMe Targeted in Data Breach The Messenger · Claire Cameron
- This follows several years of warnings about the potential vulnerabilities and risks associated with direct to consumer genetic testing companies like #23andme. In 2019, for example, the Pentagon sounded the alarm over home DNA kits, citing concerns that “outside parties are exploiting the use of genetic materials for questionable purposes,” including mass surveillance & unauthorized tracking. … @rvawonk@newsie.social · Caroline Orr Bueno
- A security researcher told me he found his wife's information in the #23andMe files, which had 1 million users of Ashkenazi heritage and 300,000 users of Chinese heritage — 23andMe first denied the leak then said it was due to scraping — https://therecord.media/... @jgreig@ioc.exchange · Jon Greig
- @Techmeme This is not what decentralization looks like. If you can pause your blockchain, it isn't decentralized. @rizzn@blockriot.com · Mark Rizzn Hopkins
- Very few cybersecurity breaches shake me to the core but this is absolutely one of those breaches. “The initial data leak was limited … Breanna H.
- Here's the problem with this. I am in this database. (We all are for that matter.). I never used their service. I've never even gone to their homepage. … Caston Thomas
- Will there be a free ‘DNA monitoring service’ for those potentially impacted? — “On Sunday, a post on a popular forum where stolen data … Corey Munson
- This proves someone is trying to clone me. :) — https://lnkd.in/... Martin Bally
- 23andMe scraping incident leaked data on 1.3M users Hacker News
- 23andMe Scraping Incident Leaked Data On 1.3 Million Users Slashdot · BeauHD
- Private 23andMe user data is up for sale after online scraping spree Ars OpenForum
Discussion
-
@dangillmor@mastodon.social
Dan Gillmor
on mastodon
Latest catastrophic data breach involves a company storing some of the most sensitive possible information about individuals. There will be no consequences apart from damaging those people's lives, of course — because there is no accountability for any of this. …
-
@tiffanycli@mastodon.social
Tiffany Li
on mastodon
Consumer DNA testing company 23andMe is investigating a potential data breach: — Threat actor used credentials exposed in other leaks to access legitimate 23andMe user accounts and scrape data, including “tailored ethnic groupings,” like 1 million lines of data on Ashkenazi peo…
-
@23andmesupport
@23andmesupport
on x
@DarkWebInformer @23andMe Following a claim that someone had gained access to and is selling certain 23andMe customer data, we conducted an investigation. We have not identified any unauthorized access to our systems. We will continue to monitor the situation.
-
@shuttlecock
Brad Stephenson
on x
Important context concerning the 23andMe “data leak”. Their systems weren't actually hacked. The culprits simply used login credentials from hacks concerning other sites or services. This is why you should use a unique password for each online service you use.
-
@mrwilgus
Wade Wilgus
on x
23andMe story reminds me of this “be gay do crime” historical badass [image]
-
@kategoestech
@kategoestech
on x
Multiple @23andme patients' data has been stolen through the compromised login data Full names, profile photos, sex, date of birth, genetic ancestry, and geographical location are now known to the hackers Theoretically, this could be used to create targeted biological weapons [im…
-
@rvawonk
Caroline Orr Bueno, Ph.D
on x
The 23AndMe hackers claim to have genetic data belonging to Mark Zuckerberg, Elon Musk, and Sergey Brin (a cofounder of Google whose ex-wife is the founder of 23AndMe), among other “celebrities.” [image]
-
@23andmesupport
@23andmesupport
on x
Following a claim that someone had gained access to and is selling certain 23andMe customer data, we conducted an investigation. We have not identified any unauthorized access to our systems. We will continue to monitor the situation.
-
@troyhunt
Troy Hunt
on x
So apparently, “we have not identified any unauthorised access” considers hackers logging in with stolen credentials “authorised access” 🤷♂️ Poor description IMHO, especially when it could have been so succinctly and clearly explained https://www.bleepingcomputer.com/ ...
-
@mattjay
Matt Johansen
on x
23andMe's RESPONSE: The company confirmed the data's legitimacy. They believe the hackers used credentials from other breaches to access 23andMe accounts. “We do not have any indication at this time that there has been a data security incident within our systems.” [image]
-
@jgreigj
Jon Greig
on x
A security researcher told me he found his wife's information in the #23andMe files, which had 1 million users of Ashkenazi heritage and 300,000 users of Chinese heritage 23andMe first denied the leak then said it was due to scraping @TheRecord_Media https://therecord.media/...
-
@mattjay
Matt Johansen
on x
The compromised accounts had opted into the platform's ‘DNA Relatives’ feature. The hacker accessed a few 23andMe accounts and scraped the data of their DNA Relative matches, showing the potential risks of such features. [image]
-
@mattjay
Matt Johansen
on x
TARGETED LEAK: The initial data leak was limited but deeply concerning. The threat actor released 1 million lines of data specifically for Ashkenazi people. This targeted attack raises serious questions about the motive behind the breach. [image]
-
@weldpond
Chris Wysopal
on x
What gets collected gets stolen and resold. Information wants to be freely available for a price. https://cyberscoop.com/...
-
@andrejonker
@andrejonker
on x
Just saving this article link here for my next use case example of “data not stored, cannot be stolen”. Friends don't let friends buy DNA “tests” for fun 😋 #privacy https://cyberscoop.com/...
-
r/cybersecurity
r
on reddit
Genetics firm 23andMe says user data stolen in credential stuffing attack
-
r/Jewish
r
on reddit
23andMe scraping incident leaked data on 1.3 million users of Ashkenazi and Chinese descent
-
r/technology
r
on reddit
23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews
-
r/worldnews
r
on reddit
23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews
-
r/IronFrontUSA
r
on reddit
23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews
-
r/privacy
r
on reddit
Genetics firm 23andMe says user data stolen in credential stuffing attack
-
r/Judaism
r
on reddit
23andMe User Data Stolen in Targeted Attack on Ashkenazi Jews
-
r/inthenews
r
on reddit
Genetics firm 23andMe says user data stolen in credential stuffing attack.
-
r/NewsOfTheStupid
r
on reddit
“23andMe” says user data stolen. On October 4, the threat actor offered to sell data profiles in bulk for $1-$10 per 23andMe account, depending on how many were purchased. …
-
r/23andme
r
on reddit
23andMe Warns of Hacker Breaking Into User Accounts
-
r/TrueAnon
r
on reddit
Hackers steal genetic data from 23andme, specifically targeting accounts of Ashkenazi Jews
-
r/InfoSecNews
r
on reddit
Genetics firm 23andMe says user data stolen in credential stuffing attack