Skip to content
cisonews.net

Incident · 8-K Item 7.01

23andMe reports credential stuffing that exposed DNA Relatives profile data

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

23andMe Holding, the consumer genetics company, disclosed on October 10, 2023 that profile information users share through its DNA Relatives feature had been accessed from individual accounts without authorization. It said it had no indication of a breach within its own systems; the accounts were reached with usernames and passwords reused from other sites.

October 10 filing

The company said it was working to confirm what data was accessed.

December 1 amendment

The 8-K/A dated the start of public awareness to an online post on October 1, 2023, and gave the share of accounts directly accessed. Through those accounts, the actor reached a significant number of files with profile information about other users who had opted in to DNA Relatives. For a subset of the directly accessed accounts, health-related information derived from genetics was involved. 23andMe required password resets on October 10 and two-step verification from November 6, and expected $1 million to $2 million in one-time expenses.

Not given

Neither filing states the total number of users whose profile data was exposed.

Sources

  1. 2023-10-10 · A23andMe Holding Co., Form 8-K (SEC EDGAR), published October 10, 2023
  2. 2023-12-01 · A23andMe Holding Co., Form 8-K/A (SEC EDGAR), published December 1, 2023

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.