23andMe Holding Co.
bd_ab14d4ca29340e51 · schema v1 · pii pii-v1
Full breach record for 23andMe Holding Co. →23andMe, Inc. notified Delaware residents of a credential stuffing attack occurring between May 2023 and September 2023. A threat actor used compromised credentials to access accounts linked to the optional DNA Relatives feature, exposing ancestry data, DNA segments, and profile information. 23andMe engaged forensic experts, required password resets and two-step verification, and is working with federal law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline
May 1, 2023
Begins
Oct 1, 2023
Discovered
Oct 10, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- SEC 8-Kbd_cd8db4669b886a802023-10-10Verified
- SEC 8-Kbd_c6928174f9265a872023-12-01 · +52dVerified
- Delaware State AGbd_983bec69f67e0ced2023-12-15 · +66dVerified
- California State AGbd_29c164e09dc57f932024-01-21 · +103dVerified
Filing propagation · 5 filings · 2 states
View merged incident ↗Pattern: first filing Oct 10, last Jan 21 (CA) — a 103-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.