Finance

Should I Delete My 23andMe Account Based on Latest Data Breach and Privacy Reports

In late 2023, 23andMe disclosed a credential-stuffing attack that exposed data of roughly 6.9 million users, with some profiles including genetic ancestry and trait reports. The...

Mara Ellison
Should I Delete My 23andMe Account Based on Latest Data Breach and Privacy Reports

23andMe Data Breach Timeline and Scope

In late 2023, 23andMe disclosed a credential-stuffing attack that exposed data of roughly 6.9 million users, with some profiles including genetic ancestry and trait reports. The breach involved access to accounts where users reused passwords from other services, and 23andMe stated it notified affected users and reset compromised tokens. Forbes reported that hackers offered data for millions of 23andMe users for sale on hacking forums, with certain profile details bundled in low-cost packages. The incident drew scrutiny from regulators and increased attention on genetic data as a high-value target for cybercriminals.

23andMe confirmed that the breach affected users who had not enabled two-factor authentication and that the stolen data included shared DNA relatives, ancestry composition, and some health predisposition reports. The company said it implemented additional security measures, including mandatory 2FA prompts and enhanced monitoring, following the incident. Security researchers noted that genetic data cannot be changed like a password, making such breaches uniquely risky for long-term privacy. The breach timeline shows initial unauthorized access attempts in October 2023, with public disclosure following in November 2023.

The FTC filed a complaint against 23andMe in 2024, alleging the company failed to implement reasonable security practices and misrepresented its data protection measures after the breach. The complaint highlighted that 23andMe did not adopt multi-factor authentication by default and did not maintain a comprehensive information security program as claimed in its privacy policy. The SEC also reviewed disclosures around the breach, with 23andMe updating its filings to detail the financial and reputational impact of the incident. These actions raised questions about whether the company’s privacy and security practices met evolving regulatory standards.

Following the FTC complaint, 23andMe agreed to a settlement that included requirements to implement a comprehensive security program, undergo independent audits, and provide clearer disclosures about data use. The settlement also barred the company from making misleading claims about the security of genetic data. Legal experts noted that the case sets a precedent for how genetic testing companies are expected to handle sensitive biometric information under U.S. consumer protection law. The outcome has influenced how other direct-to-consumer genetic firms review their own security and compliance postures.

Risks of Keeping Genetic Data With 23andMe

Keeping genetic data with 23andMe means trusting the company with information that can reveal ancestry, health predispositions, and biological relationships, and that data can be used for research or shared with third parties under certain terms. 23andMe’s privacy policy states that de-identified data may be used for research and that users can opt out, but critics note that re-identification of genetic data is possible with external datasets. The company has also partnered with pharmaceutical firms for drug development, raising questions about how long genetic profiles remain under user control. Deleting your account removes future data contributions but does not guarantee that previously shared or stored data is fully erased from backups or partner systems.

Users considering deletion should review 23andMe’s data retention policies and understand that some information may persist in aggregated or anonymized form even after account removal. The deletion process typically involves requesting account closure through the settings dashboard, but the company advises that certain data may remain in backups for a defined period as required by law or for operational purposes. Security analysts recommend deleting accounts if you no longer use the service and have not opted into research sharing, especially after high-profile breaches. For more on FTC data security guidance, see the FTC’s consumer protection resources, and for broader genetic privacy considerations, visit the National Institutes of Health’s genetics privacy overview.

How to Delete Your 23andMe Account

Related Reading

More pages in this topic cluster.

Glen Benton Bass Net Worth, Career, and Latest Financial Profile

Glen Benton Bass is a private individual associated with the Bass family, a prominent American business and investment family known for their diversified holdings in energy, rea...

Read next
Best Age Spot Removers for Effective Skin Treatment

Effective age spot removers rely on active ingredients such as hydroquinone, retinoids, vitamin C serums, and azelaic acid, which are clinically documented to reduce hyperpigmen...

Read next
House of Guinness Patrick: Family Office Structure, Investments, and Net Worth

The House of Guinness is a prominent Irish family office historically tied to the Guinness brewing dynasty. Patrick Guinness, a direct descendant of the founding family, serves...

Read next