← Case Files · The Breach Files

2023 · Genetic testing

23andMe, 2023: 14,000 accounts opened the door to 6.9 million people

Case file · 4 min read · Published 14 September 2026

People affected
about 6.9 million people, from 14,000 compromised accounts
When it happened
April – September 2023
Made public
October 2023
How they got in
Credential stuffing with passwords from earlier breaches, amplified by the DNA Relatives feature
Attributed to
Unidentified; data was advertised on a hacking forum
What it cost
A $30 million settlement, a joint UK and Canadian regulatory finding, and the company's later bankruptcy

What was exposed: Names · Profile photos · Birth years · Locations · Ancestry and ethnicity estimates · Relationship labels between matched relatives

Nobody broke into 23andMe. Attackers logged in — to about 14,000 accounts, using email and password pairs recycled from other companies' breaches. Because of one feature designed to connect relatives, those 14,000 logins exposed the profile data of roughly 6.9 million people, almost none of whom had done anything wrong.

What happened

From April 2023, attackers ran credential stuffing against 23andMe: automated login attempts using pairs harvested from unrelated breaches, on the reliable assumption that a percentage of people reuse passwords. Around 14,000 accounts accepted them.

That alone would have been a minor incident. What made it a major one was DNA Relatives — an opt-in feature that shows a user other customers who share DNA with them, along with display names, relationship estimates, locations, birth years and ancestry results.

The amplification, in one sentence. Compromising one account exposes everyone that account can see. With a feature designed to connect you to hundreds of genetic relatives, 14,000 compromised accounts became 6.9 million exposed profiles — a multiplier of roughly 500. The people in that 6.9 million had strong passwords, two-factor authentication and good habits, and none of it mattered, because their exposure depended on a stranger's choices.

The company became aware of the problem in October 2023, after data from the breach was advertised on a hacking forum. It required password resets and later made two-factor authentication mandatory for all accounts.

The ethnicity lists

This is the part that separates 23andMe from an ordinary credential-stuffing incident. The data advertised for sale was not offered as a generic dump. Subsets were promoted specifically as lists of people with Ashkenazi Jewish ancestry — around a million records — and of people with Chinese ancestry.

A list of named people, with locations, organised by ethnic origin, is not a fraud resource. It is a targeting resource, and its appearance amid rising antisemitic violence was understood as such immediately. The harm model here is not financial loss; it is the possibility of someone being found.

Genetic ancestry also cannot be changed, revoked or reissued, and it is not solely yours: your results describe your siblings, your parents and your children, none of whom consented to the test you took.

Who is responsible when the password was the customer's?

23andMe's initial public position emphasised that the credentials were recycled from other breaches and that the accounts belonged to users who had reused passwords. That is factually true and it did not survive regulatory scrutiny.

The joint UK and Canadian investigation focused on what the company was in a position to control:

  1. Two-factor authentication was optional, on a service holding genetic data, until after the breach.
  2. Credential stuffing detection was inadequate for the pattern of automated logins that ran for months.
  3. The amplification through DNA Relatives was a design decision. A feature that lets one compromised account read thousands of other people's profiles needs controls proportional to that reach.
  4. The response was slow relative to how long the activity had been running.

The principle established is worth remembering: when your product design turns one weak password into thousands of victims, the design is the finding, not the password.

The afterlife of the data

23andMe's troubles did not end with the breach. The company's commercial position deteriorated and it filed for bankruptcy protection in 2025, which raised a question that had been theoretical until then: what happens to the genetic data of millions of people when the company holding it is sold for parts?

Several US state attorneys general issued advisories telling residents how to delete their data and request destruction of their samples. It is the sharpest available illustration that a privacy policy is a promise by a going concern, and a going concern is not a permanent state.

The timeline

  1. April 2023 — Credential stuffing begins.
  2. August–September 2023 — Bulk scraping through DNA Relatives continues largely undetected.
  3. October 2023 — Data is advertised on a hacking forum, including ethnicity-specific subsets; 23andMe confirms the incident and forces password resets.
  4. November 2023 — Two-factor authentication is made mandatory for all accounts.
  5. December 2023 — The company confirms approximately 6.9 million profiles were affected.
  6. 2024 — A $30 million class settlement is agreed.
  7. 2025 — UK and Canadian regulators publish joint findings; the company enters bankruptcy proceedings.

What it changed

Mandatory MFA arrived for sensitive consumer services. Optional two-factor authentication on a genetic database is now understood as a design defect rather than a user choice.

Social features got reassessed for aggregation risk. Any feature that shows one user information about many others is now a recognised amplification vector, in genealogy, dating, fitness and social apps alike.

The question of data in insolvency became live. Regulators and legislators started asking what happens to sensitive datasets when the company holding them fails — a question the privacy framework of most countries answers badly.

If you used a genetic testing service

  1. Turn on two-factor authentication everywhere it exists, and treat any service holding health or genetic data as requiring it.
  2. Review relative-matching and profile visibility settings. Opting out of matching removes you from the amplification path entirely.
  3. Consider deleting data and requesting sample destruction if you no longer use the service. Most providers document this; it is worth doing while the company still exists to process the request.
  4. Remember it is not only your decision. Testing exposes information about relatives who never consented, and that is a conversation worth having with them rather than for them.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Was 23andMe hacked?

Not in the sense of a system being breached. Attackers logged into roughly 14,000 individual accounts using email and password pairs recycled from other companies' breaches — credential stuffing. The accounts worked because those customers had reused passwords and had not turned on two-factor authentication.

How did 14,000 accounts become 6.9 million people?

Through DNA Relatives, an opt-in feature that shows you other users who share DNA with you, along with their display name, relationship estimate and profile details. Once inside one account, an attacker could see everyone matched to it. Multiply across thousands of accounts and the exposure compounds far beyond the accounts actually compromised.

Was raw genetic data stolen?

Not raw sequence data. What was exposed was profile information and the derived results: ancestry composition, ethnicity estimates, birth years, locations, and how users were related to one another. That is still genetic information about a person, and it is not information they can change.

Why was the ethnicity data particularly serious?

Because of how it was used. Subsets of the stolen data were advertised specifically as lists of people with Ashkenazi Jewish ancestry and of people with Chinese ancestry. A dataset organised by ethnicity, with names and locations attached, is a targeting list, and that is why this breach is discussed in terms of physical safety rather than fraud.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →