A Hacker Guessed 14,000 Recycled Passwords. 6.9 Million People's DNA Data Went Out the Door.

23andMe let a credential-stuffing attack on 14,000 accounts expose the genetic data of 6.9 million people, then went bankrupt and sold what was left of that data back to the CEO who was running it when the breach happened.

Share
A Hacker Guessed 14,000 Recycled Passwords. 6.9 Million People's DNA Data Went Out the Door.
Photo by Philipp Katzenberger / Unsplash

In April 2023, someone began trying stolen passwords — recycled from breaches at other, unrelated companies — against 23andMe accounts. It worked on about 14,000 of them. From those 14,000 accounts, the attacker used a built-in feature called DNA Relatives to reach outward and scrape ancestry, health-predisposition, and family-tree data belonging to roughly 6.9 million people who had never had their own password stolen at all. 23andMe did not tell the public until October 2023, and only after the stolen data turned up for sale on Reddit and a hacking forum.

Two years later, the company that let that happen filed for bankruptcy, and the genetic profiles of more than 15 million customers went up for sale as an asset of the bankruptcy estate — bid on by a pharmaceutical giant, and ultimately bought back by the same co-founder who had run the company when the breach occurred.

A Five-Month Gap

The UK's Information Commissioner's Office, which fined 23andMe £2.31 million in June 2025, laid out the timeline plainly: the credential-stuffing attack began in April 2023, and 23andMe did not publicly acknowledge it until October 2023 — a five-month gap the ICO said the company spent missing "many opportunities to act." Investigator John Edwards put it more bluntly: "23andMe failed to take basic steps to protect this information. Their security systems were inadequate, the warning signs were there, and the company was slow to respond."

The ICO's investigation identified three specific deficiencies: no mandatory multi-factor authentication and weak password requirements, no safeguards to stop bulk downloading of raw genetic data once an account was accessed, and no effective monitoring to detect the intrusion while it was happening. 23andMe did not finish addressing the underlying vulnerabilities until the end of 2024.

One Password, Many Relatives

  • April 2023: Credential-stuffing attack begins, using username/password combinations leaked in breaches at other companies.
  • ~14,000 accounts are directly accessed using reused, previously compromised passwords — not a breach of 23andMe's own systems.
  • Via the opt-in DNA Relatives feature, the attacker scrapes profile data connected to those accounts, reaching roughly 5.5 million additional DNA Relatives profiles.
  • Family Tree data belonging to a further 1.4 million users is also accessed through the same connections.
  • October 6, 2023: 23andMe first discloses the breach publicly, after stolen data appears listed for sale online.
  • Total confirmed affected: approximately 6.9 million profiles worldwide, roughly 6.4 million of them U.S. residents, according to court filings in the resulting litigation.

The data taken was not the kind that shows up in a typical breach notice. Alongside names and emails, it included ancestry composition, health-predisposition reports, and — because DNA Relatives exists specifically to map connections between users — the family relationships of people who had never signed up for the feature themselves, inherited into the exposure by virtue of being someone's genetic match.

The Bill

More than 40 class-action lawsuits over the breach were consolidated into a single federal case. 23andMe reached a $30 million settlement, given preliminary court approval in September 2024. After the company entered bankruptcy in March 2025, plaintiffs' attorneys went back to court arguing the original sum undervalued the claims now that a sale was generating fresh proceeds; the settlement was revised upward to $50 million in September 2025, funded out of the bankruptcy estate — meaning the company's own liquidation became the "only source of monetary recovery for victims," per court filings. A parallel settlement covered roughly 300,000 affected Canadian customers for CA$4.49 million.

Texas pursued its own action separately. Attorney General Ken Paxton secured a $150 million settlement against 23andMe specifically over the breach's exposure of Texans' genetic data — on top of, not instead of, the federal class settlement.

From $3.5 Billion to Chapter 11

23andMe went public via SPAC merger in 2021 at a valuation of roughly $3.5 billion. The stock spent the following years sliding — a decline the breach accelerated but did not start, as the company's consumer testing-kit business was already shrinking and it had never turned a consistent profit. Co-founder and CEO Anne Wojcicki made repeated attempts to take the company private, all rejected by 23andMe's own special board committee over concerns her offers undervalued the company and lacked committed financing.

23andMe filed for Chapter 11 bankruptcy in March 2025. Among the assets on the table: its consumer genetic-testing business, its research-services arm, the Lemonaid Health telehealth subsidiary it had acquired in 2021 — and the genetic and health data of more than 15 million customers, now legally categorized as property of the bankruptcy estate.

The Auction

In May 2025, pharmaceutical company Regeneron emerged as the winning bidder in the bankruptcy auction, offering $256 million for substantially all of 23andMe's assets. Wojcicki, who had resigned as CEO on the day of the bankruptcy filing, came back with a higher bid through a new nonprofit entity she had formed, TTAM Research Institute, and pushed to have the auction reopened. It was. TTAM's revised bid of $305 million won, and the U.S. Bankruptcy Court for the Eastern District of Missouri approved the sale in July 2025 — putting the company, and the data, back under the control of the person who had been running it during the breach.

Twenty-eight state attorneys general filed suit in the bankruptcy court in June 2025 to block the data transfer outright, arguing 23andMe had no legal authority to treat biological samples and genotype data as a freely transferable asset without customers' explicit consent — that doing so, in their filing's framing, treated sensitive genetic material as ordinary property rather than something closer to medical information. The sale proceeded regardless; a separate, broader coalition of attorneys general later reached a multistate settlement of bankruptcy-related claims against the estate in 2026, resolving allegations tied to the original breach rather than reversing the transfer itself. Multiple state AG offices issued consumer alerts in the meantime, telling 23andMe customers their best available option was to request deletion of their own data before the sale closed.

Nothing about DNA Relatives was a bug. It worked exactly as designed — matching strangers to blood relatives they'd never met, using data those relatives hadn't necessarily agreed to expose to anyone. What 23andMe didn't design for was a stranger with someone else's recycled password, and by the time 6.9 million people found out that was the same thing, the company holding what was left of their genetic profiles was already for sale to the highest bidder — which turned out, after a reopened auction, to be the person who'd been in charge when it happened.


Filed from public reporting:

Read more

A Hand-Tightened Blind Flange and a Botched Shift Handover Killed 167 Men on Occidental Petroleum's Piper Alpha Platform in 22 Minutes. No One at the Company Was Ever Criminally Charged.

A Hand-Tightened Blind Flange and a Botched Shift Handover Killed 167 Men on Occidental Petroleum's Piper Alpha Platform in 22 Minutes. No One at the Company Was Ever Criminally Charged.

At around 10 p.m. on July 6, 1988, a pressure safety valve that had been pulled for maintenance that morning let gas condensate leak past a blind flange that had only been hand-tightened. Within 22 minutes, the Piper Alpha platform, 120 miles northeast of Aberdeen in the North

By The Complaints Department
Netflix Spent Six Years Telling Customers Love Is Sharing a Password. Once It Started Charging $7.99 a Month Per Shared Password Instead, Subscriber Growth Hit Its Best Year Since the Pandemic.

Netflix Spent Six Years Telling Customers Love Is Sharing a Password. Once It Started Charging $7.99 a Month Per Shared Password Instead, Subscriber Growth Hit Its Best Year Since the Pandemic.

On March 10, 2017, Netflix's official Twitter account posted four words that would follow the company around for the next six years: "Love is sharing a password." It was a promo tweet for a show called Love, but it was also, unmistakably, a policy statement — an

By The Complaints Department
New York Paused Congestion Pricing for 'Affordability' Weeks Before a 2024 Election, Then Relaunched It at a Lower Price Once Voting Was Over. A Year Later, Traffic Was Down 11 Percent and the Federal Government Was Still in Court Trying to Kill It.

New York Paused Congestion Pricing for 'Affordability' Weeks Before a 2024 Election, Then Relaunched It at a Lower Price Once Voting Was Over. A Year Later, Traffic Was Down 11 Percent and the Federal Government Was Still in Court Trying to Kill It.

On June 5, 2024, Governor Kathy Hochul stood before reporters and "indefinitely paused" New York's Central Business District Tolling Program, the long-planned congestion charge for driving into Manhattan below 60th Street. The launch was three weeks away. Hochul cited affordability concerns for working- and middle-

By The Complaints Department
Twitter Cut Off the Third-Party Apps That Built Its Developer Ecosystem in January 2023 With No Warning. One of Those Apps Coined the Word Tweet and Designed Twitter's Bird Logo Before Twitter Had Either.

Twitter Cut Off the Third-Party Apps That Built Its Developer Ecosystem in January 2023 With No Warning. One of Those Apps Coined the Word Tweet and Designed Twitter's Bird Logo Before Twitter Had Either.

On January 13, 2023, Twitter's API went dark for third-party client apps with no announcement and no explanation. Tweetbot, Twitterrific, Fenix, and others simply stopped working, all at once, for everyone. Developers spent days guessing whether it was a bug, an outage, or deliberate. Four days later,

By The Complaints Department