Skip to main content
Breach Signal

Breach report

Genetics

23andMe

23andMe confirms hackers stole ancestry data on 6.9 million users

Hackers used recycled passwords to break into about 14,000 23andMe accounts, then scraped relative-matching data on roughly 6.9 million people, a breach that helped push the genetic testing company into bankruptcy.

Reported by TechCrunch

Records exposed

6.9M

About 6.9 million users

Scale vs. largest on file

When
2023
How they got in
Credential stuffing amplified by the DNA Relatives data-sharing feature
Sector
Genetics

In October 2023, a hacker began advertising data scraped from 23andMe on cybercrime forums, including lists that singled out users with Ashkenazi Jewish and Chinese ancestry. The consumer genetics company initially described the incident as limited, but in December 2023 it confirmed that information on about 6.9 million people, roughly half its customer base, had been exposed. The forum posts that singled out specific ethnic groups raised fears that genetic data could be used to target people for harassment.

The attackers did not breach 23andMe's core systems. Instead, they used credential stuffing, trying usernames and passwords leaked from other sites, to log into about 14,000 accounts whose owners had reused passwords and lacked two-factor authentication. From those accounts, they harvested information visible through the opt-in DNA Relatives feature, which lets genetic matches see one another's profiles. That design multiplied the damage: about 5.5 million people had DNA Relatives profiles exposed, including names, birth years, relationship labels, shared DNA percentages, ancestry breakdowns and locations, and about 1.4 million more had family tree information accessed.

23andMe forced password resets, made two-factor authentication mandatory, and drew criticism for a letter to lawyers suggesting that users who reused passwords bore responsibility. Dozens of lawsuits followed, and the company agreed in 2024 to a proposed $30 million class settlement. In June 2025, the U.K. Information Commissioner's Office fined 23andMe 2.31 million pounds, finding it had failed to implement appropriate security.

The breach compounded 23andMe's financial decline. In March 2025 the company filed for Chapter 11 bankruptcy protection, and co-founder Anne Wojcicki stepped down as chief executive. The sale of its genetic database alarmed privacy advocates and state attorneys general, who urged customers to delete their data and challenged whether genetic information could be transferred to a buyer. After a court-supervised auction, a nonprofit led by Wojcicki acquired the company's assets in mid-2025.

The episode is a landmark for genetic privacy. DNA data cannot be reset like a password, and it reveals information about relatives who never signed up. It also showed that security weaknesses at the user level, combined with social features that expose data to strangers, can turn a small number of compromised accounts into a population-scale leak.

More from the wire

More in Genetics.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.