23andMe says hackers stole the ancestry data of 6.9M of its 14M customers, via a breach first disclosed in October 2023, by leveraging access to ~14K accounts
https://arstechnica.com/... John / @obeto@mas.to : That's the problem with biometric PIIs: they cannot be changed if a breach occurs. — If, some of the victims work in sensitive departments of our security organs where entry is validated against their DNA, wouldn't that person be out of a job? — Shouldn't the person? https://gizmodo.com/... Jason Lefkowitz / @jalefkowit@octodon.social : There are a shocking number of people working in PR who do not understand what the phrase “on background” actually means — https://techcrunch.com/... [image] Andrew Abernathy / @andrewabernathy@mastodon.social : “23andMe declared part of its email as “on background,” which requires that both parties agree to the terms in advance. TechCrunch is printing the reply as we were given no opportunity to reject the terms.” — https://techcrunch.com/... Brandon Haber / @malderi@techhub.social : Be sure to change your parents and grandparents at least every six months, and use a strong mix of different genetics. https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb@infosec … : NEW: Whoopsies. — After 23andMe initially said its data breach hit 0.1% of customers (~14k). The company now reveals that — actually — there were 6.9 million victims, roughly 50% of all its customers. — The number is so high because by hacking those ~14k accounts hackers were then able to get data from relatives, who opted-into automatically sharing their data to others. … Bluesky: Mary Branscombe / @marypcbuk.bsky.social : every time I see a headline, the number of users who had data stolen goes up like it's replicating in a test tube [embedded post] @waxmonkey.bsky.social : even if companies actually tried to protect your data, its existence in their servers is a fundamental risk you dont need [embedded post] X: Merry Katemas / @katebevan : and this, my children, is why I don't do consumer DNA tests. Once your genetic data is out there, it's out there. You can't pull it back. And remember, if you do a DNA test, you're also uploading at least some of your family members' DNA too. https://techcrunch.com/... Eric Geller / @ericgeller : Second company in two weeks to revise a data breach impact estimate wayyyy upward, after Okta. Emin Gün Sirer / @el33th4xor : It's all fun and games until some kid gets a hold of DNA data, decides he's sick of throwing rocks at tanks and builds a crispr-based pathogen that kills an entire race. We need to have much better safeguards around DNA data. https://techcrunch.com/... Nikhil Krishnan / @nikillinit : well I guess inadvertently the 23andMe hack now gives a ballpark amount for how much a genetic database is worth? [image] Troy Hunt / @troyhunt : Compromised accounts via credential stuffing can be just the initial point of entry. When you have a business model like @23andMe's where *by design* it connects people together, 14k quickly becomes 7M https://www.scmagazine.com/... Sean Lyngaas / @snlyngaas : Another example of the PR playbook of staking out the early ground of “less than ____% of our customers are affected by this breach” not aging well: https://x.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: 23andMe initially said its data breach hit 0.1% of customers (~14k). 23andMe now reveals that — actually — there were 6.9 million victims. Number is so high because by hacking those ~14k accounts hackers then were able to get data from relatives. https://techcrunch.com/... Forums: Hacker News : 23andMe confirms hackers stole ancestry data on 6.9M users r/cybersecurity : 23andMe confirms hackers stole ancestry data on 6.9 million users | TechCrunch r/BillBurr : Hackers stole ancestry data of 6.9 million users, 23andMe finally confirmed r/Morocco : I know you guys like ancestry tests, take care r/worldnews : Hackers stole ancestry data of 6.9 million users, 23andMe finally confirmed r/technology : 23andMe confirms hackers stole ancestry data on 6.9 million users Ars OpenForum : Hackers stole ancestry data of 6.9 million users, 23andMe finally confirmed
Context & Ripple Effects
The incident expanded from October reports of user data circulating on hacker forums, which 23andMe attributed to credential stuffing, into a far larger exposure than the initially compromised-account count suggested. A later report of a possible 4M-record leak under investigation had already pointed to a widening scope.
The key distinction is that access to roughly 14,000 accounts reportedly exposed ancestry information tied to millions of customers. That turns an account-security failure into a data-architecture problem: information associated with one user can create consequences for many others.
First-order effects
- 23andMe customers whose ancestry data was taken face exposure even if their own accounts were not among the approximately 14,000 accessed; the reported affected population is 6.9M out of 14M customers.
- The disclosure makes clear that the breach’s impact cannot be measured solely by the fraction of accounts accessed, despite an earlier filing describing access to 0.1% of user accounts.
Second-order effects
- 23andMe will face scrutiny over how account access enabled retrieval of ancestry data at this scale, while customers may reassess the privacy trade-off of participating in ancestry-sharing features.
- Other consumer genetic-data services may need to test whether compromised accounts can expose information connected to non-compromised users, rather than treating credential-stuffing defenses as a sufficient containment boundary.
Third-order effects
- If this pattern recurs, consumer data services will increasingly be judged on the blast radius of an account takeover—not just on whether passwords and individual accounts were secured.
- Genetic-data platforms may face sustained pressure to limit how broadly relationship and ancestry data can be surfaced after a single account compromise, because affected people cannot simply replace the underlying personal data.
The trend: The breach is part of a broader shift toward evaluating privacy incidents by the networked reach of exposed data rather than the number of accounts directly breached.