Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› 23andMe Breach 2023: How Credential Stuffing on 18,000…
Breach analysis Incident: 29 Apr 2023

23andMe Breach 2023: How Credential Stuffing on 18,000 Accounts Exposed Genetic Data on Nearly 7 Million People

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 7 min read
On this page

Between April and October 2023, an attacker logged in to more than 18,000 23andMe customer accounts using passwords stolen from other websites. Through the DNA Relatives feature, each compromised account exposed profile information about many other customers it was matched with, so the breach reached almost 7 million people. Regulators in the UK and Canada found that 23andMe missed clear warning signs and lacked basic protections such as mandatory multi-factor authentication. This is a human identity breach, but it shows how automated login abuse and over-connected features turn a small number of weak credentials into a mass data leak.

Key takeaways

  • Credential stuffing began on 29 April 2023 and ran for five months. Regulators found more than 18,000 accounts were accessed directly.
  • The DNA Relatives feature let each compromised account see matched relatives' profiles, so almost 7 million customers were affected worldwide, including almost 320,000 in Canada and 155,600 in the UK.
  • Warning signs were missed: over one million login attempts in a single day in July 2023, and a claim of data theft in August 2023 that was dismissed as a hoax.
  • Fewer than 22 percent of customers used MFA or single sign-on, passwords needed only eight characters, and account monitoring could not detect anomalous behaviour.
  • The UK ICO fined 23andMe £2.31 million in June 2025, and in July 2026 42 US states reached an $18 million settlement. 23andMe filed for bankruptcy in March 2025.

At a glance

Organisation23andMe
When29 April to October 2023; became public in October 2023
AttackerUnnamed attacker who advertised the data for sale online
Entry pointCredential stuffing against the customer login page
Identities abusedCustomer (human) accounts with passwords reused from other breaches
ImpactMore than 18,000 accounts accessed; almost 7 million people affected via DNA Relatives
CategoryHuman identity (not listed as an NHI or AI agent breach)

What happened

According to the joint investigation by the Privacy Commissioner of Canada and the UK Information Commissioner, the attack began on 29 April 2023. Over five months, the attacker "used stolen log-in details (username or email address and password) from other websites impacted by previous breaches and then 'stuffed' these credentials into 23andMe's log-in page until they found matches". In total, they got into more than 18,000 customer accounts.

Direct access to those accounts was only part of the damage. 23andMe's DNA Relatives feature shows each user profile information about the people they are genetically matched with. From each compromised account, the attacker could collect data on many other customers who had never had their own passwords exposed. The regulators found that almost 7 million customers were affected worldwide.

The investigation describes several missed signals. In July 2023 the attacker made more than one million login attempts in a single day, causing an outage. In August 2023 a claim of data theft affecting over 10 million users arrived through 23andMe's customer service portal and was dismissed as a hoax. The breach only became public in October 2023, when the attacker advertised the stolen data for sale online.

The regulators also found weak protections. Fewer than 22 percent of customers had opted into multi-factor authentication or single sign-on. Passwords had to be at least eight characters with minimal complexity requirements. And logging and monitoring of account activity "was insufficient to detect anomalous user behaviours".

Timeline

DateEvent
29 April 2023Credential stuffing begins.
July 2023More than one million login attempts in one day cause an outage.
August 2023A data theft claim via the customer service portal is dismissed as a hoax.
October 2023Stolen data is advertised for sale; the breach becomes public.
March 202523andMe files for Chapter 11 bankruptcy.
June 2025UK ICO fines 23andMe £2.31 million; joint UK and Canada findings published.
July 2025TTAM Research Institute acquires 23andMe for $305 million.
July 202642 US states reach an $18 million settlement.

How it happened: the identity attack path

  1. Reused passwords. Customers used the same email and password on 23andMe as on sites that had been breached before.
  2. Automated login attempts. The attacker ran leaked credential lists against the login page at scale, over one million attempts in a day at one point.
  3. No second factor for most users. With MFA optional and used by fewer than 22 percent, a matching password was enough.
  4. Weak detection. Monitoring did not flag the unusual login volume or account behaviour as an attack in time.
  5. Over-connected data. Each compromised account could reach profile data of many matched relatives, multiplying the impact far beyond the accounts actually broken into.

Impact

  • People: almost 7 million customers worldwide, including almost 320,000 in Canada and 155,600 in the UK.
  • Data: profile and ancestry information visible through DNA Relatives, including sensitive genetic-relationship data.
  • Regulatory: the Canadian and UK regulators found breaches of PIPEDA and UK GDPR; the ICO fined 23andMe £2.31 million.
  • Legal and business: a 42-state $18 million settlement in July 2026, a Chapter 11 filing in March 2025 and the sale of the company to TTAM Research Institute.

What this means for identity security

23andMe is on our list because it shows two identity failures compounding each other. The first is familiar: optional MFA and weak password rules on a service holding extremely sensitive data, with no effective defence against automated login attacks. The second is design: a feature that let one account read data about thousands of other people meant that a small number of compromised identities exposed millions.

Both lessons apply to non-human identities. Credential stuffing is itself automation, and defending against it means treating unusual login volume, like any unusual machine behaviour, as a signal worth acting on. And any identity, human or machine, whose access fans out across many other users' data needs a far higher level of protection than an ordinary account. The same reasoning applies to API keys and service accounts that can query data about many customers at once.

Recommendations

  • Make MFA mandatory for sensitive data, or at least require it for accounts that can see other people's data. See our Workforce Identity Security Guide.
  • Defend against credential stuffing. Rate-limit logins, detect login bursts across many accounts, and check passwords against breached-password lists.
  • Design for blast radius. Limit how much data one account can reach about others, and add friction or re-authentication for bulk access.
  • Take breach claims seriously. Have a process to investigate data-theft claims and outage anomalies as potential incidents.
  • Apply the same logic to machine identities. API keys and service accounts that can read many customers' data need scoping, monitoring and short lifetimes. Our NHI Authentication Guide covers the options.

Frequently asked questions

How was 23andMe hacked?

Through credential stuffing: the attacker used email and password combinations leaked from other websites to log in to more than 18,000 23andMe accounts where customers had reused their passwords.

Why were almost 7 million people affected if only 18,000 accounts were accessed?

The DNA Relatives feature let each compromised account see profile information about its genetic matches, so the attacker could collect data on many customers whose own accounts were never accessed.

Is the 23andMe breach a non-human identity breach?

No, the accounts were human customer accounts. We include it because it shows how automated attacks and over-connected access multiply the impact of weak authentication, lessons that apply equally to API keys and service accounts.

Snowflake breach · Zacks breach · Human vs Non-Human Identity · IAM and IGA Basics

How NHI Mgmt Group can help

Attackers target whichever identity is least protected, human or machine. Our NHI Foundation Level Training Course helps teams extend strong authentication, least privilege and monitoring to service accounts, API keys, tokens and AI agents.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org