23andMe Data Breach Timeline and Scope
In late 2023, 23andMe disclosed a credential-stuffing attack that exposed data of roughly 6.9 million users, with some profiles including genetic ancestry and trait reports. The breach involved access to accounts where users reused passwords from other services, and 23andMe stated it notified affected users and reset compromised tokens. Forbes reported that hackers offered data for millions of 23andMe users for sale on hacking forums, with certain profile details bundled in low-cost packages. The incident drew scrutiny from regulators and increased attention on genetic data as a high-value target for cybercriminals.
23andMe confirmed that the breach affected users who had not enabled two-factor authentication and that the stolen data included shared DNA relatives, ancestry composition, and some health predisposition reports. The company said it implemented additional security measures, including mandatory 2FA prompts and enhanced monitoring, following the incident. Security researchers noted that genetic data cannot be changed like a password, making such breaches uniquely risky for long-term privacy. The breach timeline shows initial unauthorized access attempts in October 2023, with public disclosure following in November 2023.
Regulatory and Legal Actions Involving 23andMe
The FTC filed a complaint against 23andMe in 2024, alleging the company failed to implement reasonable security practices and misrepresented its data protection measures after the breach. The complaint highlighted that 23andMe did not adopt multi-factor authentication by default and did not maintain a comprehensive information security program as claimed in its privacy policy. The SEC also reviewed disclosures around the breach, with 23andMe updating its filings to detail the financial and reputational impact of the incident. These actions raised questions about whether the company’s privacy and security practices met evolving regulatory standards.
Following the FTC complaint, 23andMe agreed to a settlement that included requirements to implement a comprehensive security program, undergo independent audits, and provide clearer disclosures about data use. The settlement also barred the company from making misleading claims about the security of genetic data. Legal experts noted that the case sets a precedent for how genetic testing companies are expected to handle sensitive biometric information under U.S. consumer protection law. The outcome has influenced how other direct-to-consumer genetic firms review their own security and compliance postures.
Risks of Keeping Genetic Data With 23andMe
Keeping genetic data with 23andMe means trusting the company with information that can reveal ancestry, health predispositions, and biological relationships, and that data can be used for research or shared with third parties under certain terms. 23andMe’s privacy policy states that de-identified data may be used for research and that users can opt out, but critics note that re-identification of genetic data is possible with external datasets. The company has also partnered with pharmaceutical firms for drug development, raising questions about how long genetic profiles remain under user control. Deleting your account removes future data contributions but does not guarantee that previously shared or stored data is fully erased from backups or partner systems.
Users considering deletion should review 23andMe’s data retention policies and understand that some information may persist in aggregated or anonymized form even after account removal. The deletion process typically involves requesting account closure through the settings dashboard, but the company advises that certain data may remain in backups for a defined period as required by law or for operational purposes. Security analysts recommend deleting accounts if you no longer use the service and have not opted into research sharing, especially after high-profile breaches. For more on FTC data security guidance, see the FTC’s consumer protection resources, and for broader genetic privacy considerations, visit the National Institutes of Health’s genetics privacy overview.