23andMe, a genetic testing platform based in San Francisco was involved in a breach back in October, when hackers obtained the user data of about 0.1% or about 14,000 people in a technique called credential stuffing.
“Credential stuffing is a known threat and relies on the reuse of passwords across multiple services, highlighting the importance of unique passwords and the use of multi-factor authentication,” said Javvad Malik, lead security awareness advocate at KnowBe4.
“Companies holding such sensitive data must constantly evaluate their security posture and educate users about the best security practices.”
As a result, the hackers successfully accessed the personal information of 14,000 of the customer base. But from this data, hackers were able to view information shared by genetically linked relatives, leading to 6.9 million members being impacted.
Of the 6.9 million compromised accounts, 5.5 million contained information on genetic matches, potentially including birth dates and locations if provided by users. Additionally, 1.4 million accounts, part of the “Family Tree” feature, had limited access to some DNA profile information.
To address the security lapse, 23andMe is in the process of notifying affected customers and has taken immediate steps to enhance account security.
Recommended reading
- Cyber Attack Targets UK HR Provider — BBC, Boots, British Airways Impacted
- 75% of Large Businesses Suffered Security Breaches in 2019
- Customer and Employee Details Account for 45% of all Stolen Data
Users are now required to reset passwords, and the company has implemented a two-factor authentication process, involving the issuance of a temporary code to users’ mobile phones.
“The lack of specific details regarding the extent of the impact on the “significant number” of files and the users connected through the DNA Relatives feature raises serious concerns. In an era where cyber threats are increasingly sophisticated, organizations must continuously assess and enhance their security posture,” said Erfan Shadabi, cybersecurity expert at comforte AG.
“The 23andMe breach serves as a stark reminder of the need for organizations to be proactive in securing sensitive data and adopting advanced security measures to protect both their customers and the broader ecosystem of interconnected users”





