All vulnerabilities
CRITICALOpSec

OPSEC-23ANDME-2023

Consumer/genomics · 23andMe

Summary

Disclosed October 6, 2023, 23andMe was hit by a credential-stuffing campaign running from about April 2023, in which the attacker reused username/password pairs leaked from unrelated prior breaches. Because many users reused passwords, roughly 14,000 accounts were directly compromised; 23andMe's own systems were not breached, but it failed to detect or throttle the automated logins and did not enforce MFA. From those accounts, the attacker abused the opt-in DNA Relatives and Family Tree features to scrape data on approximately 6.9 million additional individuals, including names and ancestry estimates, with curated ethnicity lists advertised for sale. Downstream fallout included an approximately $30 million class-action settlement, regulatory fines, and the company's eventual bankruptcy.

References

Related vulnerabilities

All OpSec →