HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedHEALTH_GENETICHEALTH_BASICIDENTITY_BASICLOCATIONPIIMediumContained
23andMe Research Institute
bd_29c164e09dc57f93 · schema v1 · pii pii-v1
Full breach record for 23andMe Research Institute →23andMe disclosed a credential stuffing attack occurring between late April and September 2023, discovered on October 1, 2023. Threat actors used compromised credentials to access customer accounts, exfiltrating DNA Relatives profile data, genetic health reports, and personal settings. The company engaged forensic experts, notified law enforcement, forced password resets, and mandated two-step verification.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_983bec69f67e0cedDelaware State AGfiled 2023-12-15(37d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579679
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2024
- Raw hash
- b41ea12d9d75d5dd71c83ea56c11f66a4c82e489433768b7bca156e7bb2a3300
Reporting entity
- Name
- 23andMe Research Institutenorm: 23andme research institute
- Domain
- 23andmeresearchinstitute.org
Victim entity
- Name
- 23andMe Research Institutenorm: 23andme research institute
- Domain
- 23andmeresearchinstitute.org
Incident
- Discovered
- Oct 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- HEALTH_GENETICHEALTH_BASICIDENTITY_BASICLOCATIONPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Contacted federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 16 weeks(112 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.