A Hacker Guessed 14,000 Recycled Passwords. 6.9 Million People's DNA Data Went Out the Door.
23andMe let a credential-stuffing attack on 14,000 accounts expose the genetic data of 6.9 million people, then went bankrupt and sold what was left of that data back to the CEO who was running it when the breach happened.
In April 2023, someone began trying stolen passwords — recycled from breaches at other, unrelated companies — against 23andMe accounts. It worked on about 14,000 of them. From those 14,000 accounts, the attacker used a built-in feature called DNA Relatives to reach outward and scrape ancestry, health-predisposition, and family-tree data belonging to roughly 6.9 million people who had never had their own password stolen at all. 23andMe did not tell the public until October 2023, and only after the stolen data turned up for sale on Reddit and a hacking forum.
Two years later, the company that let that happen filed for bankruptcy, and the genetic profiles of more than 15 million customers went up for sale as an asset of the bankruptcy estate — bid on by a pharmaceutical giant, and ultimately bought back by the same co-founder who had run the company when the breach occurred.
A Five-Month Gap
The UK's Information Commissioner's Office, which fined 23andMe £2.31 million in June 2025, laid out the timeline plainly: the credential-stuffing attack began in April 2023, and 23andMe did not publicly acknowledge it until October 2023 — a five-month gap the ICO said the company spent missing "many opportunities to act." Investigator John Edwards put it more bluntly: "23andMe failed to take basic steps to protect this information. Their security systems were inadequate, the warning signs were there, and the company was slow to respond."
The ICO's investigation identified three specific deficiencies: no mandatory multi-factor authentication and weak password requirements, no safeguards to stop bulk downloading of raw genetic data once an account was accessed, and no effective monitoring to detect the intrusion while it was happening. 23andMe did not finish addressing the underlying vulnerabilities until the end of 2024.
One Password, Many Relatives
- April 2023: Credential-stuffing attack begins, using username/password combinations leaked in breaches at other companies.
- ~14,000 accounts are directly accessed using reused, previously compromised passwords — not a breach of 23andMe's own systems.
- Via the opt-in DNA Relatives feature, the attacker scrapes profile data connected to those accounts, reaching roughly 5.5 million additional DNA Relatives profiles.
- Family Tree data belonging to a further 1.4 million users is also accessed through the same connections.
- October 6, 2023: 23andMe first discloses the breach publicly, after stolen data appears listed for sale online.
- Total confirmed affected: approximately 6.9 million profiles worldwide, roughly 6.4 million of them U.S. residents, according to court filings in the resulting litigation.
The data taken was not the kind that shows up in a typical breach notice. Alongside names and emails, it included ancestry composition, health-predisposition reports, and — because DNA Relatives exists specifically to map connections between users — the family relationships of people who had never signed up for the feature themselves, inherited into the exposure by virtue of being someone's genetic match.
The Bill
More than 40 class-action lawsuits over the breach were consolidated into a single federal case. 23andMe reached a $30 million settlement, given preliminary court approval in September 2024. After the company entered bankruptcy in March 2025, plaintiffs' attorneys went back to court arguing the original sum undervalued the claims now that a sale was generating fresh proceeds; the settlement was revised upward to $50 million in September 2025, funded out of the bankruptcy estate — meaning the company's own liquidation became the "only source of monetary recovery for victims," per court filings. A parallel settlement covered roughly 300,000 affected Canadian customers for CA$4.49 million.
Texas pursued its own action separately. Attorney General Ken Paxton secured a $150 million settlement against 23andMe specifically over the breach's exposure of Texans' genetic data — on top of, not instead of, the federal class settlement.
From $3.5 Billion to Chapter 11
23andMe went public via SPAC merger in 2021 at a valuation of roughly $3.5 billion. The stock spent the following years sliding — a decline the breach accelerated but did not start, as the company's consumer testing-kit business was already shrinking and it had never turned a consistent profit. Co-founder and CEO Anne Wojcicki made repeated attempts to take the company private, all rejected by 23andMe's own special board committee over concerns her offers undervalued the company and lacked committed financing.
23andMe filed for Chapter 11 bankruptcy in March 2025. Among the assets on the table: its consumer genetic-testing business, its research-services arm, the Lemonaid Health telehealth subsidiary it had acquired in 2021 — and the genetic and health data of more than 15 million customers, now legally categorized as property of the bankruptcy estate.
The Auction
In May 2025, pharmaceutical company Regeneron emerged as the winning bidder in the bankruptcy auction, offering $256 million for substantially all of 23andMe's assets. Wojcicki, who had resigned as CEO on the day of the bankruptcy filing, came back with a higher bid through a new nonprofit entity she had formed, TTAM Research Institute, and pushed to have the auction reopened. It was. TTAM's revised bid of $305 million won, and the U.S. Bankruptcy Court for the Eastern District of Missouri approved the sale in July 2025 — putting the company, and the data, back under the control of the person who had been running it during the breach.
Twenty-eight state attorneys general filed suit in the bankruptcy court in June 2025 to block the data transfer outright, arguing 23andMe had no legal authority to treat biological samples and genotype data as a freely transferable asset without customers' explicit consent — that doing so, in their filing's framing, treated sensitive genetic material as ordinary property rather than something closer to medical information. The sale proceeded regardless; a separate, broader coalition of attorneys general later reached a multistate settlement of bankruptcy-related claims against the estate in 2026, resolving allegations tied to the original breach rather than reversing the transfer itself. Multiple state AG offices issued consumer alerts in the meantime, telling 23andMe customers their best available option was to request deletion of their own data before the sale closed.
Nothing about DNA Relatives was a bug. It worked exactly as designed — matching strangers to blood relatives they'd never met, using data those relatives hadn't necessarily agreed to expose to anyone. What 23andMe didn't design for was a stranger with someone else's recycled password, and by the time 6.9 million people found out that was the same thing, the company holding what was left of their genetic profiles was already for sale to the highest bidder — which turned out, after a reopened auction, to be the person who'd been in charge when it happened.
Filed from public reporting:
- HIPAA Journal — 6.9 Million 23andMe Users Affected by Data Breach
- The Register — 23andMe Hit With £2.3M Fine After Exposing Genetic Data of Millions
- HIPAA Journal — 23andMe Requests Bankruptcy Judge Approve Revised $50 Million Data Breach Settlement
- ClassAction.org — 23andMe Data Breach Settlement: $30M Deal Covers Millions Whose Info Was Stolen
- Texas Attorney General — Attorney General Paxton Secures $150 Million Settlement Against 23andMe Over Data Breach That Exposed Genetic Information of 6.9 Million People
- CNBC — Anne Wojcicki to Buy Back 23andMe and Its Data for $305 Million
- GenomeWeb — Bankruptcy Court Approves TTAM Research Institute Acquisition of 23andMe
- Courthouse News Service — States Sue to Block 23andMe From Auctioning Genetic Data in Bankruptcy Plan
- The Washington Post — States Claim 23andMe Can't Sell Customer Data Without Explicit Consent
- Colorado Attorney General — Attorney General Phil Weiser Announces Multistate Settlement of Bankruptcy Claims Against 23andMe Over Genetic Data Breach
- Fox Business — 23andMe Co-Founder Anne Wojcicki Regains Control of Bankrupt Genetic Testing Company
- Quinn Emanuel — Quinn Emanuel Secures an Unprecedented Win for Anne Wojcicki and TTAM Research Institute in 23andMe Bankruptcy Auction