ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Biotech firm 23andMe confirms user data leak in credential-stuffing attack

Biotechnology firm 23andMe, renowned for its DNA testing kits, has confirmed that user data, including photos, full names, geographical locations, and other sensitive information, has surfaced on hacker forums.

 

The company emphasized that no genetic testing results have been compromised in the breach, attributed to a credential-stuffing attack, which involves using compromised user information, such as usernames and passwords, obtained from one organization to gain unauthorized access to another.

 

However, 23andMe clarifies that this incident did not appear to be a breach of its internal systems but involved individual account breaches. According to a 23andMe spokesperson, "Thus far, our investigation has found that no genetic testing results have been leaked." The company has taken swift action upon detecting suspicious activity and has initiated a thorough investigation.

 

The breach initially surfaced with the leak of approximately "1 million lines of data for Ashkenazi people." By October 4, this data was sold in bulk on hacker forums, with increments ranging from 100 to 100,000 profiles. The extent of the attack remains unclear, but the consequences could be far-reaching, potentially affecting a substantial number of 23andMe’s users.

 

One factor that may have amplified the breach’s impact is 23andMe’s ’DNA Relatives’ feature. This feature identifies genetic relatives by comparing user DNA with that of other 23andMe members who participate in the service. After infiltrating numerous profiles through credential-stuffing, the threat actor behind the breach seems to have scraped ’DNA Relatives’ results, gaining access to even more sensitive data. It is worth noting that the number of relatives listed grows over time as more users join 23andMe.

 

In its fiscal year 2023 report, 23andMe disclosed that it had "genotyped" approximately 14 million customers, making it one of the largest repositories of genetic information globally. Since its public listing in 2021, 23andMe has been under heightened scrutiny regarding its data protection practices, which is unsurprising given the sensitive medical data it handles, including information related to disease predispositions such as Alzheimer’s, Type 2 diabetes, and cancer. On its official website, the company asserts that it exceeds industry standards for data protection.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543