23andMe user data breached in credential-stuffing attack

Biotech company 23andMe, known for its DNA testing kits, confirmed to BleepingComputer that its user data is circulating on hacker forums. The company said the leak occurred through a credential-stuffing attack.

A credential-stuffing attack involves user information that has already been compromised (usernames and passwords, for example) from one organization, which a hacker obtains and attempts to reuse with a second organization — in this case, 23andMe. Because of the nature of credential-stuffing, it does not appear this was a breach of the company's internal systems. Rather, accounts were broken into piecemeal. The perpetrators of this attack appear to have obtained quite sensitive information from the compromised accounts (genetic testing results, photos, full names and geographical location, among other things).

The initial leak comprised “1 million lines of data for Ashkenazi people,” according to BleepingComputer. By October 4, data was being offered for sale in bulk, in increments of 100, 1,000, 10,000 or 100,000 profiles. The scale of the attack is as yet unknown, but the scope of its impact has likely been exacerbated by 23andMe's 'DNA Relatives' feature. "Relatives are identified by comparing your DNA with the DNA of other 23andMe members who are participating in the DNA Relatives feature," the company states. After accessing an unknown number of profiles via credential-stuffing, the threat actor behind this breach apparently scraped the 'DNA Relatives' results for those profiles, netting much more sensitive data. According to the same FAQ page, "The number of relatives listed [..] grows over time as more people join 23andMe." For the fiscal year 2023, the company reported it “genotyped” around 14 million customers.

Ever since 23andMe went public in 2021, the company has faced extra scrutiny for its data protection practices — rightly so, since it deals with sensitive medical data derived from saliva sampling, including predispositions for diseases like Alzheimer's, Type 2 diabetes and even cancer. On its website the company claims it "exceeds" data protection standards for its industry.

This article originally appeared on Engadget at https://www.engadget.com/23andme-user-data-breached-in-credential-stuffing-attack-231757254.html?src=rss https://www.engadget.com/23andme-user-data-breached-in-credential-stuffing-attack-231757254.html?src=rss
Létrehozva 1y | 2023. okt. 7. 1:30:16


Jelentkezéshez jelentkezzen be

EGYÉB POSTS Ebben a csoportban

'Clair Obscur: Expedition 33' preview: Stunning visuals, innovative combat, prime melodrama

I’ve been wondering why everyone seems so hyped on Clair Obscur: Expedition 33. It’s the debut game from Sandfall Interactive, an independent French studio with fewer than 30 employees, an

2025. márc. 3. 14:50:17 | Engadget
The iPad mini 7 is back on sale for $100 off

Apple’s

2025. márc. 3. 14:50:16 | Engadget
How to clean your AirPods

It didn’t take long for wireless earbuds to become

2025. márc. 3. 10:20:32 | Engadget
XTRIS is a fast-paced arcade-style Playdate game you won’t be able to put down

I love a game that screams things like “neato!” and “godlike!” while I’m feverishly pressing buttons and darting my eyes around the screen, trying to make my fingers work as fast as my brain. My sk

2025. márc. 3. 1:10:08 | Engadget
Lenovo gave its latest 16-inch ThinkBook a bevy of funky concept screen accessories

The ThinkBook line has sort of become Lenovo’s de facto testing ground for far-out ideas and ambitious concepts. See the

2025. márc. 3. 1:10:07 | Engadget
The Lenovo Solar PC Concept feels like a device whose time has come

You might be surprised to learn that the first laptop with built-in solar panels is nearly 15 years old. But to

2025. márc. 3. 1:10:06 | Engadget
Lenovo's new AI laptops for MWC include the Yoga Pro 9i Aura edition and the IdeaPad Slim 3x

Lenovo has announced new laptops with generative AI features for this year's Mobile World Congress (MWC), including the

2025. márc. 3. 1:10:05 | Engadget