RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · October 2023 event · prepared 16 September 2026

Reused passwords let one credential-stuffing attack reach millions

23andMe's DNA Relatives feature meant a small share of compromised accounts exposed data on many more relatives.

Visual for this record: Reused passwords let one credential-stuffing attack reach millions
Visual published by blogger.googleusercontent.com, shown for identification of the record. Credit: blogger.googleusercontent.com · source page ↗ Rights: owner-review-pending.

What happened

23andMe disclosed in October 2023 that intruders had accessed a number of customer accounts using credential stuffing, the practice of trying usernames and passwords leaked from other websites against a different service. In its 8-K filed on 10 October 2023, the company said it found no evidence of a security incident within its own systems, and that the attacker succeeded only where a customer's 23andMe username and password matched credentials already exposed elsewhere. A later amendment filed on 1 December 2023 put the affected share at about 0.1 percent of accounts, but said the attacker also obtained a significant number of files containing profile information about other users' ancestry, shared through the optional DNA Relatives feature, and that this generally included ancestry information and, for a subset of accounts, health-related information based on the user's genetics.

23andMe's own public statement, first published 6 October 2023 and updated through 5 December 2023, described requiring all customers to reset their passwords and making two-step verification mandatory from 6 November 2023, alongside engaging forensic experts and federal law enforcement.

Confidence and limits

The scope figures and mechanism come from the company's own regulatory filings and public statements; no independent forensic or government report is part of this record. The company's description of DNA Relatives exposure as a downstream effect of a small number of compromised accounts is consistent across both filings, which supports it, but the total number of profiles ultimately affected is not stated precisely in the documents reviewed here, only described as significant.

Why it mattered

DNA Relatives was designed to connect people to genetic relatives who had also used the service, which meant that compromising one account could expose information about relatives who had never reused a password anywhere themselves. A feature built to multiply useful connections between users also multiplied the number of people affected by a single compromised login, at a ratio the company itself did not fully quantify in the documents cited here.

Defensive takeaway

Use a unique password for any service that stores sensitive personal data, particularly genetic or health information, and turn on two-factor authentication wherever it is offered, since this incident shows that a service's own systems can remain uncompromised while its users are still harmed through reused credentials.

  • Do you reuse a password across a genetic-testing, health or financial account and any other service where a breach has ever occurred?
  • Does a service you use let you see and control what an optional relative-matching or data-sharing feature exposes to other users?
  • Would two-factor authentication on your own accounts have stopped a credential-stuffing attempt using a password leaked elsewhere?

The incident did not require a flaw in 23andMe's own systems, only a percentage of customers who had reused a password, which is a reminder that a company's security posture and its customers' password habits are two separate risks that a single feature can still combine.

Defensive takeaway

Use a unique password for any account holding sensitive personal or genetic data and enable two-factor authentication wherever it is offered, since this incident occurred without any compromise of the company's own systems.

The scope figures and mechanism come from the company's own regulatory filings and public statements. No independent forensic or government report is part of this record, and the precise total number of profiles ultimately affected is not stated in the documents reviewed.

Sources & reading trail

Addressing Data Security Concerns ↗

23andMe's own account of the credential-stuffing incident, including mandatory password resets and two-step verification.

company-primary · Source published: 6 October 2023 · Retrieved: 16 September 2026

23andMe Holding Co. Form 8-K (Item 7.01) ↗

Confirms the credential-stuffing mechanism and that unauthorised access reached profile information shared via the DNA Relatives feature.

company-primary · Source published: 10 October 2023 · Retrieved: 16 September 2026

23andMe Holding Co. Form 8-K/A (amendment) ↗

Provides the updated 0.1 percent account-scope figure and describes the ancestry and health-related information exposed through DNA Relatives.

company-primary · Source published: 1 December 2023 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.