23andMe, the genetic testing provider, confirmed that hackers got hold of health reports and raw genotype data of affected customers in a credential stuffing attack that lasted five months, from April to September. The attackers used stolen credentials from other breaches or compromised online platforms. Some of the stolen data surfaced on hacking forums and the unofficial 23andMe subreddit.
The breached information involves 1 million Ashkenazi Jews and 4.1 million individuals in the UK. 23andMe revealed that the threat actor accessed customers' uninterrupted raw genotype data and possibly other sensitive information, including health reports, wellness reports, and carrier status reports.
Customers using the DNA Relatives feature might have had their DNA Relatives and Family Tree profile info scraped. This includes ancestry reports, matching DNA segments, self-reported location, ancestor birth locations, family names, profile pictures, birth years, and details from the "Introduce yourself" section.
Around 6.9 million people's data was downloaded, with 5.5 million affected through the DNA Relatives feature and 1.4 million via the Family Tree feature. In response, 23andMe mandated password resets on October 10 and implemented two-factor authentication from November 6 to thwart future credential-stuffing attempts.
The incident led to lawsuits against 23andMe, prompting the company to update its Terms of Use on November 30, making it more challenging for customers to join class action lawsuits. The company clarified that these changes aim to streamline the arbitration process and enhance customer understanding.