23andMe Research Institute
ent_174285202f5bd93417e52cc9
Disclosures
2
State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 23andMe Research Institute
- Normalized
- 23andme research institute— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- 23andmeresearchinstitute.org
Disclosure history (2)newest first
- 🐻California State AGas victim2024-01-21
23andMe disclosed a credential stuffing attack occurring between late April and September 2023, discovered on October 1, 2023. Threat actors used compromised credentials to access customer accounts, exfiltrating DNA Relatives profile data, genetic health reports, and personal settings. The company engaged forensic experts, notified law enforcement, forced password resets, and mandated two-step verification.
- 💎Delaware State AGas victim2023-12-15
23andMe, Inc. notified Delaware residents of a credential stuffing attack occurring between May and September 2023. A threat actor accessed optional DNA Relatives profile data, including ancestry reports, DNA segments, and personal details, which was posted to BreachForums. 23andMe reset passwords, enforced two-factor authentication, paused features, and engaged law enforcement and forensic experts.