{
  "type": "bundle",
  "id": "bundle--078ad837-cdef-5a3c-8aea-dd919a14bc05",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--7035280c-503d-5df6-857b-0a29c7866ab4",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:a85b82a8-5444-5690-9d91-71c382b09162",
      "name": "23andMe",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--3434b05c-01c0-506e-8bcb-824fdfca4304",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:94e9242c-6e55-5d84-88b1-3c732edd79fa",
      "name": "23andMe security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--f3e8a0b6-ce64-560f-88c5-372f5f4308ac",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:06aad2b7-b4d4-5279-b651-982bc780bf6f",
      "name": "23andMe security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1f625455-edee-5601-8821-13cbb590976e",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:16e27dc0-6097-5f42-93e2-ec774e7cf134",
      "relationship_type": "affected-organization",
      "source_ref": "incident--f3e8a0b6-ce64-560f-88c5-372f5f4308ac",
      "target_ref": "identity--7035280c-503d-5df6-857b-0a29c7866ab4",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1804591/000180459124000025/me-20231231.htm",
          "external_id": "cit:994ef311-17c7-54f0-a9f0-2aa1a33feffa",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9d22dce68884250bcf96792aa540e85299eadc4acf0f398b797cae1edefba9fb"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--21050e11-a2db-5e8c-8822-f08503578bca",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:3cf6b6f9-3c77-5f10-b1cd-5e1be1f8cbdd",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1804591/000180459124000025/me-20231231.htm",
          "external_id": "cit:4c6d4bc8-38a2-5646-8c6c-7b6fb6d3956d",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9d22dce68884250bcf96792aa540e85299eadc4acf0f398b797cae1edefba9fb"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the 23andme security incident involving 23andMe."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--40d99039-d88f-5862-8240-bfb7b6ef748b",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:56b9a505-3166-5cf2-b92a-134f4dd10c6d",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1110/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--422c4828-f01d-5fc3-8725-ed1a2efc04b4",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:bc80ce0f-cdb3-5906-9bdf-49f57bce9a2d",
      "confidence": 87,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1804591/000180459124000025/me-20231231.htm",
          "external_id": "cit:df04bbae-b53e-5006-b7e9-84e358307337",
          "description": "Using this access to the Credential Stuffed Accounts, the threat actor also accessed a significant number of files containing profile information about other users’ ancestry that such users chose to share when opting in to our DNA Relatives feature, and posted certain information online.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9d22dce68884250bcf96792aa540e85299eadc4acf0f398b797cae1edefba9fb"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Credential stuffing (reused passwords, no forced MFA) plus \"DNA Relatives\" feature scraping."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--5fe45a5d-a0fb-5d97-8f4a-311aa63d4183",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:75e54f37-6401-5baa-ad82-5b40a3cb2329",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1804591/000180459124000025/me-20231231.htm",
          "external_id": "cit:fea9a7ad-fe4d-53cb-8fa9-9ffb10076c0a",
          "description": "Based on our investigation as of the filing date of this Quarterly Report on Form 10-Q, we do not believe that there has been a data security incident within our systems, or that we were the source of the account credentials used in these attacks, and we believe that the threat actor activity is contained.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9d22dce68884250bcf96792aa540e85299eadc4acf0f398b797cae1edefba9fb"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes containment action intended to limit further access or disruption."
      }
    }
  ]
}
