ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

US genomics company 23andMe suffers a major data breach to a credential stuffing attack

Linked InXFacebook
bookmark_borderSave to Library
U.S. biotechnology and genomics company 23andMe suffered a significant cyber attack that compromised the sensitive personal information of its customers, including a large number of Ashkenazi Jews.Earlier this month, a threat actor listed 23andMe as a victim on their data leak site and shared samples of data they allegedly stole from the company, including 1 million lines of information about Ashkenazi Jews. Ashkenazi Jews are those who believe they descended from Jews who lived in Central or Eastern Europe.According to BleepingComputer, the threat actor later said that the complete stolen database had been put up for sale and quoted a price of $1-$10 per 23andMe account, depending on how many were being purchased.Acknowledging the claims of the threat actors, the company, in a statement shared with the media, said that the threat actors used previously-compromised credentials to infiltrate its internal network.“After learning of suspicious activity, we immediately began an investigation.  While we are continuing to investigate this matter, we believe threat actors were able to access certain accounts in instances where users recycled login credentials – that is, usernames and passwords that were used on 23andMe.com were the same as those used on other websites that have been previously hacked,” the company said.The compromised information includes names, usernames, profile photos, sex, dates of birth, genetic ancestry results, and geographical location. “We do not have any indication at this time that there has been a data security incident within our systems,” the company added.In a separate update on its website, 23andMe said that it is still investigating the data security incident and has engaged third-party cyber security experts to look into the matter. Also, it is working closely with federal law enforcement officials to resolve the situation.“We are reaching out to our customers to provide an update on the investigation and to encourage them to take additional actions to keep their account and password secure. Out of caution, we are requiring that all customers reset their passwords and are encouraging the use of multi-factor authentication (MFA).“If we learn that a customer’s data has been accessed without their authorisation, we will notify them directly with more information,” the company added.
Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543