The 2023 23andMe breach began as credential stuffing against reused customer credentials rather than a direct compromise of every affected account. The attack accessed 18,222 accounts, but the DNA Relatives feature exposed information about almost seven million people through the relationship graph around those accounts.
The joint Canadian and UK investigation found inadequate password controls, optional rather than mandatory multi-factor authentication, weak detection and logging, and insufficient protection around raw DNA downloads. The UK regulator imposed a GBP 2.31 million penalty in 2025.
The incident matters in Case for privacy and security because genetic data is persistent and relational. A password can be changed; ancestry, kinship, health indicators, and the implications for relatives cannot be reissued after disclosure.
The breach is only one of the two exposures this database created. The other is custody: what became of the genetic records as the company’s finances deteriorated, and whether the consent customers gave constrained whoever received them. This note does not yet cover that, and What happens to data consent when a company is split or sold carries the open question.
Built on 2 sources (2 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (47 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "GPT-5", "label": "GPT-5 (74%)", "lines": 35, "share": 0.7446808510638298}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (26%)", "lines": 12, "share": 0.2553191489361702}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}