23andMe user data breached in credential-stuffing attack

Biotech company 23andMe, known for its DNA testing kits, confirmed to BleepingComputer that its user data is circulating on hacker forums. The company said the leak occurred through a credential-stuffing attack.

A credential-stuffing attack involves user information that has already been compromised (usernames and passwords, for example) from one organization, which a hacker obtains and attempts to reuse with a second organization — in this case, 23andMe. Because of the nature of credential-stuffing, it does not appear this was a breach of the company's internal systems. Rather, accounts were broken into piecemeal. The perpetrators of this attack appear to have obtained quite sensitive information from the compromised accounts (genetic testing results, photos, full names and geographical location, among other things).

The initial leak comprised “1 million lines of data for Ashkenazi people,” according to BleepingComputer. By October 4, data was being offered for sale in bulk, in increments of 100, 1,000, 10,000 or 100,000 profiles. The scale of the attack is as yet unknown, but the scope of its impact has likely been exacerbated by 23andMe's 'DNA Relatives' feature. "Relatives are identified by comparing your DNA with the DNA of other 23andMe members who are participating in the DNA Relatives feature," the company states. After accessing an unknown number of profiles via credential-stuffing, the threat actor behind this breach apparently scraped the 'DNA Relatives' results for those profiles, netting much more sensitive data. According to the same FAQ page, "The number of relatives listed [..] grows over time as more people join 23andMe." For the fiscal year 2023, the company reported it “genotyped” around 14 million customers.

Ever since 23andMe went public in 2021, the company has faced extra scrutiny for its data protection practices — rightly so, since it deals with sensitive medical data derived from saliva sampling, including predispositions for diseases like Alzheimer's, Type 2 diabetes and even cancer. On its website the company claims it "exceeds" data protection standards for its industry.

This article originally appeared on Engadget at https://www.engadget.com/23andme-user-data-breached-in-credential-stuffing-attack-231757254.html?src=rss https://www.engadget.com/23andme-user-data-breached-in-credential-stuffing-attack-231757254.html?src=rss
Vytvorené 1y | 7. 10. 2023, 1:30:16


Ak chcete pridať komentár, prihláste sa

Ostatné príspevky v tejto skupine

Gemini live video and screensharing arrive on Android devices later this month

Mobile World Congress 2025 has officially kicked off in Barcelona. Google is on the ground pre

3. 3. 2025, 17:20:21 | Engadget
UK watchdog investigates chidren's safety on TikTok and Reddit

The UK's Information Commissioner's Office (ICO) has announced it's

3. 3. 2025, 17:20:20 | Engadget
Anker power banks and charging stations are up to 35 percent off right now

It's your lucky day if you've been looking for a good deal on a power bank or charging station.

3. 3. 2025, 17:20:19 | Engadget
Samsung Galaxy S25 series phones are on sale for record-low prices

Samsung Galaxy S25 smartphones are on sale for record-low prices, making this a great time to upgrade. The standard S25

3. 3. 2025, 17:20:18 | Engadget
'Clair Obscur: Expedition 33' preview: Stunning visuals, innovative combat, prime melodrama

I’ve been wondering why everyone seems so hyped on Clair Obscur: Expedition 33. It’s the debut game from Sandfall Interactive, an independent French studio with fewer than 30 employees, an

3. 3. 2025, 14:50:17 | Engadget
How to clean your AirPods

It didn’t take long for wireless earbuds to become

3. 3. 2025, 10:20:32 | Engadget