genetic data breach 23andMe 3 min read

The 23andMe genetic data breach and its aftermath

Published on EBM Solution

A DNA double helix beside a warning about exposed personal data

Genetic data breach 23andMe became a case study in how a weak credential practice can expose the most sensitive category of personal data. The genetics company confirmed a breach involving around four million genetic profiles, after stolen data appeared for sale on a criminal forum and a second user claimed to hold a database covering more than four million profiles, most of them belonging to residents in Germany and the United Kingdom.

How the breach happened

Internal investigations indicated that attackers used credentials already compromised elsewhere, such as usernames and passwords that victims had reused on other websites. The technique is credential stuffing: automated attempts to log in with leaked credentials across many services. The breach did not require a vulnerability in the company's systems. It exploited the habit of reusing passwords, which turns a leak on an unrelated site into access to a sensitive account.

The first disclosure, at the start of the month, reported unauthorised access to various accounts through the DNA Relatives feature, which lets users identify potential genetic matches and exposes some personal information in the process. The later leak was substantially larger than that initial exposure of 1.3 million accounts. According to the criminal who claimed responsibility, the stolen database ran to several terabytes.

Why genetic data is different

Genetic information belongs to the special categories of personal data under the GDPR, alongside health data and other sensitive information, and it carries consequences that cannot be reversed. A password can be changed; a genome cannot. The data also describes people who never used the service, because genetic matches reveal relationships and can expose relatives. That is why the exposure extends well beyond the individuals whose accounts were accessed, and why it can support discrimination, extortion and identity fraud.

The company said it would verify the validity of the exposed information and notify potentially affected users, and it faced the prospect of collective legal action alongside earlier complaints about privacy. The case illustrates a pattern that regulators have warned about: companies holding sensitive data are only as strong as the weakest credential practice among their users.

What companies should take from it

The lessons apply to any organisation holding sensitive information. Enforce multi-factor authentication on accounts that reach sensitive data, and make it resistant to phishing where possible. Detect credential stuffing with rate limiting, anomaly detection and alerts on logins from new locations. Limit what a single authenticated session can reach, so that one compromised account does not expose an entire database. Monitor for leaked credentials and require a reset when they appear. Above all, treat the sensitivity of the data as the factor that sets the security bar, because some categories of information can never be made safe again once disclosed.

Have a project in mind?

Do you know where to start?

The goal is to pin down the problem, the priorities and the timing.

Book a first call

Frequently asked questions

What is credential stuffing?

An automated attack that tries usernames and passwords leaked from one service against other services, relying on the fact that people reuse credentials.

Was there a vulnerability in 23andMe's systems?

The reported cause was credential stuffing with passwords compromised elsewhere, rather than a direct intrusion through a technical flaw in the platform.

Why is genetic data treated as special category data?

Because it is highly sensitive, it can reveal information about relatives and it cannot be changed or revoked once exposed, which the GDPR recognises with stricter rules.

How can a company reduce this risk?

By enforcing strong multi-factor authentication, detecting unusual login patterns, limiting access within systems and monitoring for leaked credentials.

Sources

Dark Reading — 23andMe hacker leaks a new tranche of stolen data: https://www.darkreading.com/attacks-breaches/23andme-hacker-leaks-new-tranche-of-stolen-data-

European Commission — data protection in the EU and the GDPR: https://commission.europa.eu/law/law-topic/data-protection_en

Garante per la protezione dei dati personali: https://www.garanteprivacy.it/

ENISA — threat landscape and credential-based attacks: https://www.enisa.europa.eu/