In October 2023, a threat actor posted a sample of 23andMe user data to a hacker forum, claiming to have stolen millions of records. The initial sample targeted Ashkenazi Jewish users specifically - 1 million profiles. A second sample posted days later contained data on 300,000 users of Chinese descent. The targeting was not random. The breach leveraged a 23andMe feature called DNA Relatives, which lets users see other users who share genetic material with them. By compromising a relatively small number of seed accounts through credential stuffing, the attacker harvested the genetic ancestry data of millions of people who had never had their own accounts compromised.
The 23andMe breach is unlike most credential theft incidents because of what was exposed. Password databases are sensitive but the harm is mostly financial and remediable - you change passwords. Genetic data is permanently identifying, cannot be changed, and reveals deeply personal information including ancestry, ethnic background, disease predispositions, and biological family relationships. It also implicates people who never consented to share their data with a commercial company - the relatives whose connections to breach victims were exposed through DNA Relatives were not necessarily 23andMe customers themselves.
Credential Stuffing as Initial Access
23andMe confirmed in its initial disclosure that the breach did not involve a compromise of 23andMe's own systems. The attacker obtained access through credential stuffing - using username/password combinations from previously leaked databases to log into 23andMe accounts. Users who had reused passwords from other breached services had their 23andMe accounts accessible to the attacker.
The scale of the initial access is not fully public. 23andMe's eventual disclosure indicated approximately 14,000 accounts were directly compromised through credential stuffing. This is a relatively small number - but those 14,000 accounts were seed nodes in a much larger network. The attacker then scraped the DNA Relatives feature, which by default showed each user's genetic matches and their associated profile data.
The Scale and Nature of the Exposed Data
23andMe's final disclosure, filed with the SEC in January 2024, stated that approximately 6.9 million users had their DNA Relatives profile data exposed. The exposed data varied by user settings but potentially included: display name, relationship labels (e.g., "2nd cousin"), location (city/zip), birth year, profile photo, shared DNA percentage, and ancestry composition percentages (the breakdown of ancestry by geographic region). For the directly compromised accounts, additional data including the full genetic ancestry composition and family tree information was accessible.
The ethnic and ancestry composition data was particularly sensitive. The initial breach samples were specifically filtered for Ashkenazi Jewish and Chinese-ancestry users - suggesting the attacker either had a specific buyer for ethnically-targeted data, or was demonstrating the capability to target specific ethnic groups to potential buyers. Genetic ancestry data revealing ethnic or religious background has historical and contemporary implications for discrimination and targeting.
The breach also exposed some users' "Health + Ancestry" data - disease predisposition reports that 23andMe provides to customers who have purchased the health tier of the service. Medical genetic information - predispositions to conditions like Alzheimer's, BRCA mutations, heart disease risk - is among the most sensitive personal data that exists. It can affect insurance, employment, and family relationships.
Legal and Regulatory Fallout
23andMe faced numerous class action lawsuits filed immediately after the breach disclosure. The company's response to the litigation included an unusual and widely criticized move: in November 2023, 23andMe updated its Terms of Service to include a mandatory arbitration clause and a class action waiver, with a 30-day opt-out window. The timing - updating terms to add class action waivers after a major breach - was perceived as an attempt to limit legal exposure from the breach. Several courts subsequently addressed whether the updated terms could apply to breach claims predating the update; the legal battles continued through 2024.
In September 2024, 23andMe reached a $30 million settlement covering approximately 6.4 million US-based breach victims. Individual payments were modest given the scale of the class - the settlement primarily required 23andMe to implement enhanced security measures, expand its privacy program, and delete certain data. The settlement was criticized by some consumer advocates as inadequate given the permanent nature of genetic data exposure.
23andMe also faced financial difficulty in 2024 unrelated to the breach. The company's stock had fallen significantly from its SPAC merger peak, and the company announced workforce reductions. CEO Anne Wojcicki (sister of YouTube CEO Susan Wojcicki) explored taking the company private and faced board opposition. The combination of the breach, the litigation, and the financial struggles raised questions about the long-term custody of 23andMe's genetic database - what happens to the data of 14 million customers if the company faces bankruptcy or acquisition?