Skip to content

23andMe

Disclosed Oct 6, 20232 years ago6,900,000 affectedSettled

Official notice

Credential stuffing exposed 6.9M users' ancestry data; UK ICO fine of GBP 2.31M

Between April and September 2023 a hacker used credentials reused from other breaches to access 23andMe accounts, exposing data on about 6.9 million users, including 155,592 UK residents. The ICO fined 23andMe GBP 2.31M, noting it lacked extra verification before raw genetic data downloads.

What is known

People affected6,900,000 (as reported by the organization)
DisclosedOct 6, 2023
DiscoveredOct 2023
HappenedApr 29, 2023
AttackCredential stuffing
Data exposedNames, Dates of birth, Location, Health, Other
SectorHealthcare · US
StatusSettled
Lawsuit or fineGBP 2.31M ICO fine (June 2025); USD 18M 43-AG settlement (July 2026) (about $21M) On Lawsuits

Sources

Notices filed

WhereFiledPeople
ResearchtotalOct 6, 20236,900,000
ResearchtotalOct 6, 20236,900,000
California AGresidents of CAJan 21, 2024
History of this record
  • 2026-09-25 · lawsuits_ref: empty to in-re-23andme-breach-mdl · weekly source
  • 2026-09-25 · fine_usd: 30000000 to 21100000 · seed source
  • 2026-09-25 · lawsuit: $30M US class action settlement (2024); UK ICO fine of GBP 2.31M (2025) to GBP 2.31M ICO fine (June 2025); USD 18M 43-AG settlement (July 2026) · seed source
  • 2026-09-25 · summary: Attackers reused passwords from other breaches to log in to 23andMe accounts between April and September 2023 and scraped profile and ancestry data shared through the DNA Relatives feature. The company later said about 6.9 million people we to Between April and September 2023 a hacker used credentials reused from other breaches to access 23andMe accounts, exposing data on about 6.9 million users, including 155,592 UK residents. The ICO fined 23andMe GBP 2.31M, noting it lacked ex · seed source
  • 2026-09-25 · title: Credential stuffing exposes DNA Relatives profiles of 6.9 million users to Credential stuffing exposed 6.9M users' ancestry data; UK ICO fine of GBP 2.31M · seed source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 30000000 · seed source
  • 2026-09-25 · lawsuit: empty to $30M US class action settlement (2024); UK ICO fine of GBP 2.31M (2025) · seed source
  • 2026-09-25 · sector: other to health · seed source
  • 2026-09-25 · attack: unknown to credential-stuffing · seed source
  • 2026-09-25 · data_types: [] to ["names","dob","location","health","other"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 6900000 · seed source
  • 2026-09-25 · disclosed: 2024-01-21 to 2023-10-06 · seed source
  • 2026-09-25 · discovered: empty to 2023-10 · seed source
  • 2026-09-25 · summary: empty to Attackers reused passwords from other breaches to log in to 23andMe accounts between April and September 2023 and scraped profile and ancestry data shared through the DNA Relatives feature. The company later said about 6.9 million people we · seed source
  • 2026-09-25 · title: empty to Credential stuffing exposes DNA Relatives profiles of 6.9 million users · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about 23andMe

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.