Hackers posted an initial data sample from 23andMe on BreachForums earlier in the week, claiming that it had 1M data points exclusively about Ashkenazi Jews
At least a million data points from 23andMe accounts appear to have been exposed on BreachForums.
WiredLily Hay Newman
Context & Ripple Effects
This report is an early, unconfirmed indication that data associated with 23andMe was being offered on BreachForums, with the claimed sample framed around a particular ancestry-linked community. Follow-up coverage said the sample appeared not to include raw genetic data, an important limit on what the posted material can establish.
The episode subsequently widened from a sample claim to a reported investigation into a possible 4 million-record leak. Later reporting also characterized the initial account access as affecting 0.1% of accounts, showing how a relatively narrow entry point can be associated with much broader exposure through connected user data.
First-order effects
People whose information may be in the sample face uncertainty over whether their account and ancestry-related details were exposed, with heightened sensitivity because the claim singles out AshkenaziJews.
23andMe must validate the material and scope of the alleged exposure, while BreachForums gains another high-sensitivity dataset listing that can be copied or resold.
Second-order effects
A public sample makes containment harder: even if it lacks raw genetic data, exposed account or profile information can enable targeting, and users may reassess whether to keep data in consumer genetic services.
The claimed scale and community-specific framing raise the cost of communicating clearly about what data was accessed, forcing 23andMe to distinguish confirmed exposure from an unverified seller claim.
Third-order effects
If credential-based access can expose information beyond the accounts initially compromised, consumer genetic-data platforms will face stronger pressure to limit cross-user data visibility and make breach scope legible.
The incident points to a broader mismatch between the longevity and sensitivity of genetic-service data and the conventional account-security controls used to protect it; the eventual impact depends on what the investigation confirms.
The trend: Consumer genetic-data breaches are making data-sharing design and account security central to trust in services built around highly durable personal information.
DNA testing company 23andMe just confirmed a potential data breach: Threat actor used credentials exposed in other leaks to access legitimate 23andMe user accounts and scrape data, including “tailored ethnic groupings,” like 1 million lines of data on Ashkenazi people... https://…
Consumer DNA testing company 23andMe is investigating a potential data breach: — Threat actor used credentials exposed in other leaks to access legitimate 23andMe user accounts and scrape data, including “tailored ethnic groupings,” like 1 million lines of data on Ashkenazi peo…
23andMe user data was seemingly stolen in a credential stuffing campaign that targeted Ashkenazi Jews. Also maybe data from Mark Zuckerberg, Elon Musk and Sergey Brin is in the leak? 23andMe seems to be confirming the incident yet hasn't validated the data https://www.wired.com/…
Latest catastrophic data breach involves a company storing some of the most sensitive possible information about individuals. There will be no consequences apart from damaging those people's lives, of course — because there is no accountability for any of this. …
I considered doing 23andMe several times, because members of my family who did got in contact with some distant Jewish relatives in Ukraine that way. But I ultimately never did it, because the thought of a private company having a database of genetic Jews seemed too scary.
23andMe user data was seemingly stolen in a credential stuffing campaign that targeted Ashkenazi Jews. Also maybe data from Mark Zuckerberg, Elon Musk and Sergey Brin is in the leak? 23andMe seems to be confirming the incident yet hasn't validated the data https://www.wired.com/.…
A security researcher told me he found his wife's information in the #23andMe files, which had 1 million users of Ashkenazi heritage and 300,000 users of Chinese heritage 23andMe first denied the leak then said it was due to scraping @TheRecord_Media https://therecord.media/...
TARGETED LEAK: The initial data leak was limited but deeply concerning. The threat actor released 1 million lines of data specifically for Ashkenazi people. This targeted attack raises serious questions about the motive behind the breach. [image]
“23andMe” says user data stolen. On October 4, the threat actor offered to sell data profiles in bulk for $1-$10 per 23andMe account, depending on how many were purchased. …