Find notable cyber news and cases, enriched with sources, timelines, and signals.

23AndMe hit by network compromise

Incident
First reported
Last updated
Happening score
H score 55
2 unique sources, 2 articles

Summary

Hide ▲

23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from April 2023 to September 2023 before being disclosed in October 2023. The compromise turned account reuse into a large-scale privacy and identity risk, with stolen data later appearing for sale on the dark web.

Related Happenings

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

23AndMe multistate genetic-data settlement and ICO fine

Regulatory/Legal Action
H score35 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

How related: A settlement of $18m has been reached between a coalition of 42 US attorneys general and genetic testing firm 23andMe following the 2023 data breach.

About this happening: 23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...

Infostealer malware operation targeting online store users

Malware Activity
H score32 First: 21.05.2026 00:36 Last: 21.05.2026 00:36 Sources 1

About this happening: A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...

Erie Family Health Centers data leak exposing credentials and medical data

Data Leak
H score65 First: 18.05.2026 15:58 Last: 18.05.2026 15:58 Sources 1

About this happening: Erie Family Health Centers disclosed a data leak that exposed 570,000 people and included credentials, financial information, and medical information. Inve...

BlackFile vishing extortion campaign targeting retail and hospitality organizations

Campaign
H score37 First: 24.04.2026 21:26 Last: 24.04.2026 21:26 Sources 1

About this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...

Timeline

  1. 17.07.2026 17:30 1 articles · 12d ago

    23andMe reaches $18m settlement with 42 US attorneys general

    Legal Policy Action Update

    23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.

    Show sources
  2. 16.07.2026 16:47 2 articles · 14d ago

    23AndMe hit by network compromise

    Initial Disclosure

    Credential-stuffing attacks against 23andMe stayed undetected for five months, enabling unauthorized access to customer accounts. The compromise ultimately exposed data on 6.9 million customers, including genetic ancestry information.

    Show sources