23andMe Holding Co.
ent_70dff2d696a9d326
Disclosures
5
State AG · SEC 8-K · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 23andMe Holding Co.
- Normalized
- 23andme holding— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- 23andme.com
Disclosure history (5)newest first
- California State AGas victim2024-01-21
23andMe disclosed a credential stuffing attack occurring between late April and September 2023, discovered on October 1, 2023. Threat actors used compromised credentials to access customer accounts, exfiltrating DNA Relatives profile data, genetic health reports, and personal settings. The company engaged forensic experts, notified law enforcement, forced password resets, and mandated two-step verification.
- Delaware State AGas victim2023-12-15
23andMe, Inc. notified Delaware residents of a credential stuffing attack occurring between May and September 2023. A threat actor accessed optional DNA Relatives profile data, including ancestry reports, DNA segments, and personal details, which was posted to BreachForums. 23andMe reset passwords, enforced two-factor authentication, paused features, and engaged law enforcement and forensic experts.
- FEDERALSEC 8-Kas victim2023-12-01
23andMe Holding Co. filed an amended 8-K (Amendment No. 1) supplementing its October 10, 2023 disclosure regarding a credential stuffing incident. A threat actor accessed a small percentage (0.1%) of user accounts using credentials from other compromised sites. The incident exposed ancestry and health-related genetic data, and the actor posted shared profile information online. 23andMe engaged forensic experts, forced password resets, and implemented mandatory two-factor authentication. The incident status is contained.
- Delaware State AGas victim2023-10-10
23andMe, Inc. notified Delaware residents of a credential stuffing attack occurring between May 2023 and September 2023. A threat actor used compromised credentials to access accounts linked to the optional DNA Relatives feature, exposing ancestry data, DNA segments, and profile information. 23andMe engaged forensic experts, required password resets and two-step verification, and is working with federal law enforcement.
- FEDERALSEC 8-Kas victim2023-10-10
23andMe Holding Co. disclosed that unauthorized individuals accessed certain profile information shared via the DNA Relatives feature. The company believes the threat actor used credentials previously compromised on other websites (credential stuffing/reuse). No indication of a security incident within 23andMe's own systems. Investigation is ongoing; forensic experts retained and law enforcement notified.