logo

23andMe: 'Negligent' Users at Fault for Breach of 6.9M Records

ID: 1ab8816b-f713-5f82-a6fd-0f1ecae0581f

STIX ID: report--1ab8816b-f713-5f82-a6fd-0f1ecae0581f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-05

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

23andMe faced lawsuits after attackers used credential stuffing to access about 14,000 accounts and obtain DNA Relatives information for nearly seven million users; the company argues the exposures resulted from users reusing passwords rather than an internal breach, describes remediations (session termination, forced password resets, law enforcement notification), and the report frames the incident as raising legal and industry questions about shared responsibility for account security and the need for stronger provider-side controls like MFA and adaptive authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.