23andMe Holding Co.
ent_70dff2d696a9d326
Disclosures
3
SEC 8-K · State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 23andMe Holding Co.
- Normalized
- 23andme holding— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- 23andme.com
Disclosure history (3)newest first
- FEDERALSEC 8-Kas victim2023-12-01
23andMe Holding Co. filed an amended 8-K (Amendment No. 1) supplementing its October 10, 2023 disclosure regarding a credential stuffing incident. A threat actor accessed a small percentage (0.1%) of user accounts using credentials from other compromised sites. The incident exposed ancestry and health-related genetic data, and the actor posted shared profile information online. 23andMe engaged forensic experts, forced password resets, and implemented mandatory two-factor authentication. The incident status is contained.
- 💎Delaware State AGas victim2023-10-10
23andMe, Inc. notified Delaware residents of a credential stuffing attack occurring between May 2023 and September 2023. A threat actor used compromised credentials to access accounts linked to the optional DNA Relatives feature, exposing ancestry data, DNA segments, and profile information. 23andMe engaged forensic experts, required password resets and two-step verification, and is working with federal law enforcement.
- FEDERALSEC 8-Kas victim2023-10-10
23andMe Holding Co. disclosed that unauthorized actors accessed certain customer profile information via the DNA Relatives feature. The incident involved the use of usernames and passwords from previously compromised third-party websites (credential stuffing). 23andMe engaged forensic experts and is cooperating with federal law enforcement. The investigation is ongoing; no specific data types or affected individual counts were disclosed.