FEDERALItem 7.01 · voluntary (Reg FD)HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICHEALTH_BASICPHILowContained
23andMe Holding Co.
bd_c6928174f9265a87 · schema v1 · pii pii-v1
Full breach record for 23andMe Holding Co. →23andMe Holding Co. filed an amended 8-K (Amendment No. 1) supplementing its October 10, 2023 disclosure regarding a credential stuffing incident. A threat actor accessed a small percentage (0.1%) of user accounts using credentials from other compromised sites. The incident exposed ancestry and health-related genetic data, and the actor posted shared profile information online. 23andMe engaged forensic experts, forced password resets, and implemented mandatory two-factor authentication. The incident status is contained.
SEC clockMateriality determined Oct 10, 2023 → Filed Dec 1, 202352d ✗ SEC 4-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ab14d4ca29340e51Delaware State AGfiled 2023-10-10(52d gap)Verified
- bd_cd8db4669b886a80SEC 8-Kfiled 2023-10-10(52d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1804591/000119312523287449/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 1, 2023
- Raw hash
- eb852984baebd35d1c61a2690e42e2e61e52b570ba0fa89dd15ab971e0e3a41e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- 23andMe Holding Co.norm: 23andme holding
- SEC CIK
- 0001804591
- Domain
- 23andme.com
Victim entity
- Name
- 23andMe Holding Co.norm: 23andme holding
- SEC CIK
- 0001804591
- Domain
- 23andme.com
Incident
- Discovered
- Oct 1, 2023
- Materiality determined
- Oct 10, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Assessing its response to notices filed by consumers under the California Consumer Privacy ActAssessing its response to inquiries from various governmental officials and agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 52d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Oct 10, 2023→ Filed: Dec 1, 202352d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.