Breach report
Genetics23andMe
23andMe confirms hackers stole ancestry data on 6.9 million users
Hackers used recycled passwords to break into about 14,000 23andMe accounts, then scraped relative-matching data on roughly 6.9 million people, a breach that helped push the genetic testing company into bankruptcy.
Reported by TechCrunch
Records exposed
6.9M
About 6.9 million users
Scale vs. largest on file
- When
- 2023
- How they got in
- Credential stuffing amplified by the DNA Relatives data-sharing feature
- Sector
- Genetics
In October 2023, a hacker began advertising data scraped from 23andMe on cybercrime forums, including lists that singled out users with Ashkenazi Jewish and Chinese ancestry. The consumer genetics company initially described the incident as limited, but in December 2023 it confirmed that information on about 6.9 million people, roughly half its customer base, had been exposed. The forum posts that singled out specific ethnic groups raised fears that genetic data could be used to target people for harassment.
The attackers did not breach 23andMe's core systems. Instead, they used credential stuffing, trying usernames and passwords leaked from other sites, to log into about 14,000 accounts whose owners had reused passwords and lacked two-factor authentication. From those accounts, they harvested information visible through the opt-in DNA Relatives feature, which lets genetic matches see one another's profiles. That design multiplied the damage: about 5.5 million people had DNA Relatives profiles exposed, including names, birth years, relationship labels, shared DNA percentages, ancestry breakdowns and locations, and about 1.4 million more had family tree information accessed.
23andMe forced password resets, made two-factor authentication mandatory, and drew criticism for a letter to lawyers suggesting that users who reused passwords bore responsibility. Dozens of lawsuits followed, and the company agreed in 2024 to a proposed $30 million class settlement. In June 2025, the U.K. Information Commissioner's Office fined 23andMe 2.31 million pounds, finding it had failed to implement appropriate security.
The breach compounded 23andMe's financial decline. In March 2025 the company filed for Chapter 11 bankruptcy protection, and co-founder Anne Wojcicki stepped down as chief executive. The sale of its genetic database alarmed privacy advocates and state attorneys general, who urged customers to delete their data and challenged whether genetic information could be transferred to a buyer. After a court-supervised auction, a nonprofit led by Wojcicki acquired the company's assets in mid-2025.
The episode is a landmark for genetic privacy. DNA data cannot be reset like a password, and it reveals information about relatives who never signed up. It also showed that security weaknesses at the user level, combined with social features that expose data to strangers, can turn a small number of compromised accounts into a population-scale leak.