23andMe hackers accessed ancestry information from thousands of customers and their DNA relatives

An SEC filing has revealed more details on a data breach affecting 23andMe users that was disclosed earlier this fall. The company says its investigation found hackers were able to access information from 0.1 percent of its userbase, or the accounts of about 14,000 of its 14 million total customers, TechCrunch notes. On top of that, the attackers were able to exploit 23andMe’s opt-in DNA Relatives feature to access “profile information about other users’ ancestry.” 23andMe hasn't said how many of these users were affected. Hackers posted information from both groups online.

When the breach was first revealed in October, the company said its investigation “found that no genetic testing results have been leaked.” According to the new filing, the data “generally included ancestry information, and, for a subset of those accounts, health-related information based upon the user’s genetics.” All of this was obtained through a credential-stuffing attack, in which hackers used login information from other, previously compromised websites to access those users’ accounts on other sites. In doing this, the filing says, “the threat actor also accessed a significant number of files containing profile information about other users’ ancestry that such users chose to share when opting in to 23andMe’s DNA Relatives feature and posted certain information online.”

Engadget has reached out to 23andMe for comment. Following the discovery of the breach, 23andMe instructed affected users to change their passwords and later rolled out two-factor authentication for all of its customers. In another update on Friday, 23andMe said it had completed the investigation and is notifying everyone who was affected. The company also wrote in the filing that it “believes that the threat actor activity is contained,” and is working to have the publicly-posted information taken down.

This article originally appeared on Engadget at https://www.engadget.com/23andme-hackers-accessed-ancestry-information-from-thousands-of-customers-and-their-dna-relatives-205758731.html?src=rss https://www.engadget.com/23andme-hackers-accessed-ancestry-information-from-thousands-of-customers-and-their-dna-relatives-205758731.html?src=rss
Établi 1y | 2 déc. 2023, 21:20:24


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

Trump has fired the director of the US Copyright Office

As first reported by

11 mai 2025, 21:30:14 | Engadget
iOS 19 may bring a feature that makes signing into public Wi-Fi less of a hassle

Apple is reportedly planning to introduce a small but welcome convenience feature with iOS 19: cross-device syncing for Wi-Fi access portals. This is according to the latest

11 mai 2025, 21:30:13 | Engadget
SoundCloud says it's never trained AI using artists' work after getting called out for terms of use change

Following backlash about a quietly added clause to SoundCloud's

11 mai 2025, 19:10:29 | Engadget
Samsung has begun taking pre-orders for its 500Hz OLED gaming monitor

It won't make you a better gamer, but Samsung's latest gaming monitor entices those hunting for faster refresh rates. The company's newest

11 mai 2025, 19:10:28 | Engadget
Scientists find lead really can be turned into gold (with help from the Large Hadron Collider)

One of the ultimate goals of medieval alchemy has been realized, but only for a fraction of a second. Scientists with the European Organization for Nuclear Research, better known as CERN, were able

11 mai 2025, 16:50:12 | Engadget
How to use Gemini to generate unique backgrounds in Google Meet

Google’s Gemini AI has been getting upgrade after upgrade

11 mai 2025, 14:30:23 | Engadget