How the 23andMe breach happened: 14,000 logins that exposed 6.9 million people
Attackers logged into only about 14,000 of 23andMe's 14 million customer accounts, roughly 0.1%, yet walked away with information on about 6.9 million people.[1] This case file covers how a handful of reused passwords turned into one of the largest genetic data breaches on record, what it cost the company, and the one control that would have stopped it at the front door.
What happened
Starting in April 2023, attackers began trying stolen email and password pairs against 23andMe's login page, with an intense burst in May and a second wave in September.[5][6] In August, when a claim surfaced online that data on more than 10 million users had been taken, the company treated it as a hoax.[5][6]
On October 1, 2023, someone posted online claiming to hold 23andMe customer data, and an employee soon found stolen profiles advertised on Reddit.[2][5] The listings were sorted by ancestry, including a set said to cover 1 million users of Ashkenazi Jewish descent and another of 100,000 users of Chinese descent.[3] The company went public with the incident in early October and required every customer to reset their password, filing a notice with the SEC on October 10.[2]
On November 6, 2023, 23andMe made a second login step mandatory for all customers; until then it had been optional.[2][3] In an updated SEC filing on December 1, the company said about 0.1% of accounts had been accessed directly, and further reporting put the total number of people exposed at about 6.9 million, nearly half its customer base.[1][2]
How they got in
This was credential stuffing: taking username and password pairs leaked from breaches at other websites and trying them on a different site, betting that some people reuse the same password everywhere.[1] The company said the accounts it found compromised used credentials that matched logins leaked elsewhere.[2] No sophisticated break-in of 23andMe's servers was needed. The front door simply accepted a correct password with nothing else required.
What turned 14,000 accounts into 6.9 million people was a feature. DNA Relatives, an opt-in tool, lets each customer see details about other customers who share DNA with them. From the accounts they controlled, the attackers were able to view and collect about 5.5 million DNA Relatives profiles, plus Family Tree information on about 1.4 million more people.[1][7] Most of those people never had their own passwords taken.[4]
Depending on the person, the exposed data included display names, birth years, rough location, profile photos, ancestry and ethnicity estimates, family trees, the percentage of DNA shared with matches and, for some, health reports based on their genetics.[1][6] Nobody's DNA sample was stolen, but for many people this was the most sensitive profile they had anywhere online.
What it cost
In its SEC filing, 23andMe estimated $1 million to $2 million in one-time costs for consultants, lawyers and other advisers.[2] That turned out to be the smallest bill. More than 30 lawsuits followed, and in a January 2024 letter to victims' lawyers the company argued that users who recycled passwords were to blame, which drew sharp public criticism.[4]
In September 2024 the company agreed to settle the U.S. class action for $30 million, including cash payments and 3 years of monitoring for affected customers, with about $25 million expected to be covered by cyber insurance.[7] On June 17, 2025, the UK Information Commissioner's Office fined 23andMe £2.31 million after a joint investigation with Canada's privacy commissioner. It found the data of 155,592 UK residents had been exposed and that the company lacked mandatory multi-factor login, strong password checks, limits on access to raw genetic data and effective threat monitoring.[5] By then the company was in Chapter 11 bankruptcy proceedings in the U.S.[5]
The missing control
The missing control: mandatory two-step verification for every account. A second login step, such as a code from an app or a text message, means a stolen password alone does not open the account.
Credential stuffing works because it only needs the one thing people leak most often. If a second step had been required before the attack instead of after it, the recycled passwords would have hit a wall, the 14,000 accounts would have stayed shut, and the DNA Relatives data behind them would never have been reachable. The UK regulator also pointed to the absence of monitoring: months of login attempts from April to September should have looked like an attack long before stolen data showed up for sale.[5][6]
What to do in your business
- Turn on two-step login everywhere it exists. Email, banking, payroll, accounting and cloud storage all offer it. Make it required for staff, not optional.
- If you run a customer login, require it there too. Or at least block logins from passwords known to be leaked and add a check when someone signs in from a new device.
- Watch for bursts of failed logins. Ask your IT provider or software vendor for an alert when many accounts see failed attempts from unfamiliar places.
- Review what one account can see. Features that show one user's data to others multiply the damage of a single stolen login. Limit sharing to what the job or service actually needs.
- Give staff a password manager. A unique password for every site means a leak somewhere else cannot be replayed against you.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- HIPAA Journal: 6.9 Million 23andMe Users Affected by Data Breach
- SEC: 23andMe Holding Co. Form 8-K/A (amended December 1, 2023)
- TechCrunch: 23andMe, Ancestry and MyHeritage move to two-factor by default
- TechCrunch: 23andMe tells victims it's their fault that their data was breached
- UK Information Commissioner's Office: ICO fines 23andMe £2.31 million for failing to protect UK users' genetic data
- Society for Computers and Law: 23andMe fined £2.31 million for failing to protect UK users' genetic data
- Lawyer Monthly: 23andMe settles data breach lawsuit for $30 million