Summary
- Environment: Genetic testing/Biotech
- Operational impact: The reviewed source does not establish a precise operational or data impact
- Financial impact: No financial figure is established by the reviewed source evidence
- Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.
What happened
In 2023, 23andMe experienced an incident in its genetic testing/biotech environment. The retained source describes the attack path as follows: Credential stuffing (reused passwords, no forced MFA) plus “DNA Relatives” feature scraping. [1]
Impact
- The reviewed source does not establish a precise affected-person count, data scope, or operational consequence.
- No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.
Threat Group & Attack Vector
The retained source describes the attack path as follows: Credential stuffing (reused passwords, no forced MFA) plus “DNA Relatives” feature scraping. The canonical record does not add intrusion steps beyond those supported by the source. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- T1110 — Brute Force — mapped from the cited behavior. [1]
Response
The retained source describes containment action intended to limit further access or disruption. [1]
This account is bounded to 23andMe Form 10-Q. Details absent from that evidence are left unresolved rather than inferred. [1]
