23andMe user profiles scraped after credential stuffing attack

Organization
23andMe
Exploit
Credential Compromise
Industry
Consumer Genetics

In early October 2023 a member of a cybercrime forum advertised what was described as roughly 20 million records belonging to customers of the consumer genetics company 23andMe. That posting, made on 1 October, linked to a sample, and the initial leak was about one million lines of data on people of Ashkenazi Jewish descent. The same actor returned days later, on 4 October, offering data in batches of 100, 1,000, 10,000 and 100,000 profiles at 1 to 10 dollars per account.

23andMe said it had no indication of a security incident within its own systems. The company attributed the theft to credential stuffing, in which attackers take usernames and passwords leaked from unrelated breaches and try them against accounts where customers had reused the same credentials.

Once inside those accounts, the attackers were able to pull profile information belonging to other customers through DNA Relatives, an opt-in feature that connects users with people identified as genetic matches. According to 23andMe, the information exposed could include display names, profile photographs, sex, birth year, location, predicted relationship to a match, percentage of shared DNA and ancestry results.

The company urged customers to enable two-factor authentication and to use unique passwords. The scale was contested at the time of reporting. The seller's totals moved between 20 million and 13 million records, 23andMe confirmed no figure, and the company's initial statements did not concede that a breach of its systems had taken place.

Updates

  1. 23andMe confirmed in early December 2023 that about 14,000 accounts were accessed directly through credential stuffing, and that profile data on roughly 6.9 million users was reached through them: about 5.5 million through DNA Relatives and 1.4 million through Family Tree. The seller's claims of 20 million and later 13 million records were never substantiated.

Sources