CSIDB logo
Incident

23andMe

Incident posture

Attack window
Oct 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-01 12:10

Linked entities

Victim
23andMe
Threat actors
0 actors
Sources
12 sources

Timeline

Occurred
Oct 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major genetic testing company suffered a significant data breach after cybercriminals used a credential stuffing attack to access customer accounts, exploiting users who recycled login passwords and lacked multi-factor authentication. The incident exposed the personal and genetic information of nearly 7 million individuals, including ancestry details, health reports, and raw DNA data, which was subsequently advertised for sale on dark web forums. Following the breach, the company faced bankruptcy, multiple class-action lawsuits, and enforcement actions from various states and international regulators, resulting in substantial financial settlements and new mandated security requirements to protect customer data going forward.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2023, 23andMe disclosed a data breach that exposed the personal and genetic information of nearly 7 million customers, roughly half of its user base at the time. The breach was the result of a credential stuffing campaign in which attackers used login credentials previously exposed in other data breaches to gain unauthorized access to 23andMe user accounts that relied on recycled usernames and passwords. The initial vector exploited approximately 14,000 accounts directly, but the attackers were then able to harvest additional information from the DNA Relatives feature, which connects users with genetic relatives who have also opted into the service. Exposed data included names, sex, birth years, locations, ancestry reports, raw genetic data, health reports, DNA shared with relatives, and the locations and birth years of biological relatives. Threat actors subsequently offered the stolen data for sale on the dark web through forums such as BreachForums, with one listing specifically advertising a "1 million Ashkenazi database" and offering bulk data packs at prices ranging from $1,000 for 100 profiles to $100,000 for 100,000 profiles. California investigators later determined that the threat actor operated within 23andMe's systems undetected for approximately five months before the breach became public.

Following the disclosure, 23andMe confirmed that the leaked data was legitimate and launched an investigation with the assistance of third-party forensic experts, while also coordinating with federal law enforcement officials. The company required all customers to reset their passwords and began mandating email two-step verification for all users, automatically enrolling both new and existing customers. 23andMe temporarily disabled certain features within the DNA Relatives tool as an additional precaution while the investigation continued. Despite these steps, state investigators and a coalition of attorneys general later alleged that 23andMe failed to employ reasonable security safeguards prior to the incident, including comparing passwords against blocklists of known breached credentials, requiring multi-factor authentication, implementing rate limiting and intrusion prevention measures, maintaining adequate logging and monitoring, investigating unusual login patterns such as a massive spike in login attempts, remediating known vulnerabilities, and properly reviewing and testing design features. California investigators identified specific red flags that the company failed to investigate, including a suspicious spike in user login attempts in July 2023 and a Reddit post in August 2023 discussing a possible breach and sale of user data.

The legal and financial fallout from the breach continued to expand over the following years. A class-action lawsuit resulted in an initial $30 million settlement that was later raised to a cap of $50 million to resolve most U.S. customer claims, receiving final approval in January 2025 with a claim deadline of February 17, 2026. The settlement provided tiered compensation, including up to $10,000 for extraordinary claims such as identity fraud or mental health treatment, $165 for health data breaches, and an additional $100 for residents of specific states. Eligible users were defined as U.S. residents who were 23andMe customers between May 1, 2023, and October 1, 2023. A separate $3.25 million settlement was reached with more than 300,000 former Canadian customers. By June 2026, the bankruptcy plan administrator and plaintiffs agreed on a final payout amount of $46.75 million, which was approved by U.S. Bankruptcy Judge Brian Walsh in St. Louis on July 7, 2026. Because $14.29 million had already been disbursed, an additional $32.46 million was set aside for distribution. The administrator resolved more than 255,860 claims, with thousands of additional claims still pending at the time of the ruling.

In March 2025, 23andMe filed for Chapter 11 bankruptcy protection, citing the data breach, related litigation, increased competition, and falling demand for genetic testing products as contributing factors. By that time, the company had collected approximately 15 million DNA samples. In June 2025, a bipartisan coalition of 28 attorneys general sued 23andMe in an effort to protect customer data during the bankruptcy proceedings, and later that year, TTAM Research Institute, a nonprofit controlled by co-founder and former CEO Anne Wojcicki, purchased 23andMe's assets for $305 million. The company was subsequently rebranded as Chrome Holding Co. In May 2026, California Attorney General Rob Bonta filed a lawsuit against Chrome Holding Co. in San Francisco Superior Court, accusing the company of failing to take adequate measures to protect sensitive data, ignoring known system vulnerabilities, failing to properly investigate warnings that its systems had been compromised, and misleading consumers about the severity of the breach. The complaint alleged violations of California's Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act, and sought millions of dollars in civil fines along with injunctions to block further violations of state privacy laws. California was reported to have been affected by the breach more than any other state, with 855,541 residents impacted. A bankruptcy judge later ruled that California could not seek monetary damages from the company because of its reorganization plan, though the state was given 14 days to either dismiss its lawsuit or amend the complaint to eliminate the claims for monetary relief.

In July 2026, a settlement of $18 million was reached between a coalition of 42 U.S. attorneys general and the bankruptcy trustee for 23andMe to resolve claims related to the data breach investigation. The total allowed claims for states amounted to $150 million, but the immediate recovery was limited to $18 million due to the limited funds in the bankruptcy estate. Michigan was slated to receive $436,605 of that amount, and 23andMe agreed to pay more than $705,000 to New York. As a condition of the settlement, new data security requirements were imposed at TTAM Research Institute to protect customer data going forward, including appropriate risk analysis, the addition of an Advisory Board on data security, and continuing to offer consumers the right to delete their information. The UK's Information Commissioner's Office fined 23andMe £2.3 million in June 2025 for failing to protect customers' special category data, and in July 2026, the Spanish privacy watchdog fined the company €2.4 million after 2,642 customers residing in Spain were identified as affected by the breach.

Sources

Sources available to members: 12 sources.

CSIDB