23andMe user profiles scraped after credential stuffing attack
- Organisation
- 23andMe
- Exploit
- Credential Compromise
- Industry
- Consumer Genetics
In early October 2023 a member of a cybercrime forum advertised what was described as roughly 20 million records belonging to customers of the consumer genetics company 23andMe. That posting, made on 1 October, linked to a sample, and the initial leak was about one million lines of data on people of Ashkenazi Jewish descent. The same actor returned days later, on 4 October, offering data in batches of 100, 1,000, 10,000 and 100,000 profiles at 1 to 10 dollars per account.
23andMe said it had no indication of a security incident within its own systems. The company attributed the theft to credential stuffing, in which attackers take usernames and passwords leaked from unrelated breaches and try them against accounts where customers had reused the same credentials.
Once inside those accounts, the attackers were able to pull profile information belonging to other customers through DNA Relatives, an opt-in feature that connects users with people identified as genetic matches. According to 23andMe, the information exposed could include display names, profile photographs, sex, birth year, location, predicted relationship to a match, percentage of shared DNA and ancestry results.
The company urged customers to enable two-factor authentication and to use unique passwords. The scale was contested at the time of reporting. The seller's totals moved between 20 million and 13 million records, 23andMe confirmed no figure, and the company's initial statements did not concede that a breach of its systems had taken place.