top of page

23andMe Breach 2023: Credential Stuffing and the Cost of Password Reuse

Dec 9, 2023
5 min read

Updated: Aug 31

Nobody broke into 23andMe. Old passwords from other companies' breaches were tried at the front door for five months, and about 14,000 still worked. A feature built to connect genetic relatives did the rest, exposing 6.9 million people, most of whom did nothing wrong.


Case type: Credential stuffing / data scraping   

Identified: Oct 5, 2023  Disclosed: Oct 6, 2023

Attribution: Actor using the handle "Golem"




Organizations invest heavily in cybersecurity technologies, security monitoring, and threat detection. Yet some of the most damaging incidents begin with something far simpler: a reused password.


The 2023 23andMe breach showed how consumer behavior can create cybersecurity risk even when an organization's systems are never directly hacked, and how an organization's own blind spots can turn that risk into catastrophe. It demonstrated the effectiveness of credential stuffing, the danger of features that connect accounts to one another, and something this series returns to often: security is never solely an organizational responsibility, and never solely an individual one either. This breach required both sides to fail. Both did.




The attack began quietly on April 29, 2023, and ran for roughly five months. According to a later joint investigation by the Canadian and UK privacy regulators, the attacker fed usernames and passwords stolen in other, unrelated breaches into 23andMe's own login page, testing combination after combination until some worked. This is credential stuffing. It doesn't require breaking into the target's systems at all; it relies on the fact that many people reuse the same password across unrelated services, and that one of those services has already been breached.


23andMe had at least three chances to catch it. In July 2023, a script attempted to log into a single account more than a million times in one day, crashing parts of the platform; the company investigated, but treated it as an isolated event. The same month, roughly 400 unauthorized profile-transfer attempts drew another isolated investigation. In August, messages through 23andMe's own customer support portal, echoing a post on a hacking forum, claimed more than 10 million user records had been stolen. The company opened a ticket, concluded the claim was a hoax, and closed it. It wasn't a hoax.



A second, more intense wave of credential stuffing followed in September. On October 1, the attacker, using the handle "Golem," advertised the stolen data for sale on Reddit and a hacking forum, including lists organized by users' racial and ethnic background. A 23andMe employee spotted the listing. Only then did the company open a full investigation, confirming internally on October 5 that a breach had occurred and disclosing it publicly the next day. Over the following weeks it terminated active sessions, forced password resets, made multi-factor authentication mandatory, and disabled the self-service raw DNA download feature, changes the regulators later concluded could and should have come far sooner.



The real scope came down to math. Roughly 14,000 accounts, about a tenth of one percent of 23andMe's customers, were directly compromised through credential stuffing. But many of those users had opted into DNA Relatives, which shares profile data with genetic matches, sometimes with as many as 5,000 connected profiles per account. By scraping those connections, the attacker turned 14,000 compromised logins into exposure for nearly 6.9 million people: roughly 5.5 million through DNA Relatives and another 1.4 million through Family Tree profiles. The vast majority had never reused a password, never been careless, and never had their own credentials stolen anywhere.





The breach began in other companies' databases


23andMe was not the source of a single one of the compromised credentials. Every username and password the attacker used had been stolen somewhere else, in breaches of unrelated services, sometimes years earlier. Yet 23andMe experienced the incident, absorbed the regulatory findings, paid the settlements, and ultimately saw the breach contribute to the end of its independent existence. The uncomfortable principle underneath:


An organization's security can be affected by security decisions made outside its environment.

Security depends not only on technology and internal controls but on the behavior of employees, customers, partners, and users, and on what an organization does when that behavior fails. The regulators' conclusion was pointed on this second half: reused passwords opened the door, but it was 23andMe's own missing controls and unconnected warnings that left it open for five months.




An attack that logs in instead of breaking in


Credential stuffing is one of the most common identity-based attack techniques, and one of the simplest:



Unlike password guessing, credential stuffing uses credentials that were once genuinely valid. The attack succeeds because human behavior is predictable: many people reuse passwords because it is convenient, and attackers build entire strategies around that assumption. To the target's systems, every successful attempt looks like a customer logging in.




The gap between knowing and doing


Most people understand that password reuse is not ideal. Many do it anyway, because managing dozens or hundreds of unique passwords is genuinely difficult. That gap between knowledge and behavior is one of the most important concepts in human risk management: risk is not always created by a lack of awareness. Often it emerges from everyday decisions, habits, and shortcuts made by people who know better and choose convenience anyway. Effective security programs focus not only on awareness but on making the secure behavior the easy one, which for passwords means managers, passkeys, and multi-factor authentication that is required rather than offered.




Some data can't be reset


The breach also demonstrates why identity protection must scale with the sensitivity of what it guards. The exposed data included ancestry, health predispositions, and family connections, information that is deeply personal and uniquely identifying. The UK Information Commissioner put it plainly, quoting one of the affected: once this information is out there, it "cannot be changed or reissued like a password or credit card number." The sale listings organized by racial and ethnic background made the stakes concrete: this was data that could be weaponized against people for what they are, not just what they own. Regulators found that despite holding this class of data, 23andMe required no multi-factor authentication and no additional verification before raw genetic data could be downloaded.




Not one decision. A set of conditions.


The question organizations should ask isn't "why do people reuse passwords?" They do, and they will. A more useful question is: what conditions turned a predictable consumer habit into one of the most consequential data breaches on record?





Both sides of the bargain failed


Organizations are responsible for securing systems, monitoring threats, enforcing authentication, and responding to incidents. Users are responsible for their side of the bargain:



Strong security outcomes require both sides. In this case, both fell short: thousands of users reused exposed passwords, and 23andMe missed three separate warning signs across several months before connecting them. The cruelest arithmetic belongs to the 6.9 million people in between, who mostly did neither.










"Security Is a Shared Responsibility."


The 23andMe breach shows how far a single ordinary habit can travel. A password reused years earlier, on a service long forgotten, became a working key to someone's genetic identity, and through a feature built for connection, to the identities of thousands of their relatives. The users who reused passwords bear their share. So does the company that saw three warnings and connected none of them.


The consequences outlived the company itself: regulatory findings on two continents, settlements measured in tens of millions, a bankruptcy that turned genetic data into an auctionable asset, and 6.9 million people whose most permanent information changed hands twice, once stolen, once sold. Technology reduces this risk. It has to, because the choices people make every day are not going to change on their own.


Because in connected systems, one person's old password can become millions of people's permanent problem.



Sources


Comments


bottom of page