23AndMe hit by network compromise
Incident
Summary
Hide ▲
Show ▼
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from April 2023 to September 2023 before being disclosed in October 2023. The compromise turned account reuse into a large-scale privacy and identity risk, with stolen data later appearing for sale on the dark web.
Related Happenings
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
23AndMe multistate genetic-data settlement and ICO fine
Regulatory/Legal Action
H score35
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
How related:
A settlement of $18m has been reached between a coalition of 42 US attorneys general and genetic testing firm 23andMe following the 2023 data breach.
About this happening:
23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...
23AndMe multistate genetic-data settlement and ICO fine
Regulatory/Legal ActionHow related: A settlement of $18m has been reached between a coalition of 42 US attorneys general and genetic testing firm 23andMe following the 2023 data breach.
About this happening: 23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...
Infostealer malware operation targeting online store users
Malware Activity
H score32
First: 21.05.2026 00:36
Last: 21.05.2026 00:36
Sources 1
About this happening:
A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...
Infostealer malware operation targeting online store users
Malware ActivityAbout this happening: A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...
Erie Family Health Centers data leak exposing credentials and medical data
Data Leak
H score65
First: 18.05.2026 15:58
Last: 18.05.2026 15:58
Sources 1
About this happening:
Erie Family Health Centers disclosed a data leak that exposed 570,000 people and included credentials, financial information, and medical information. Inve...
Erie Family Health Centers data leak exposing credentials and medical data
Data LeakAbout this happening: Erie Family Health Centers disclosed a data leak that exposed 570,000 people and included credentials, financial information, and medical information. Inve...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
Campaign
H score37
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
CampaignAbout this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
Timeline
-
17.07.2026 17:30 1 articles · 12d ago
23andMe reaches $18m settlement with 42 US attorneys general
Legal Policy Action Update23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
Show sources
- 23andMe Faces New Security Mandates in $18m Data Breach Settlement — www.infosecurity-magazine.com — 17.07.2026 17:30
-
16.07.2026 16:47 2 articles · 14d ago
23AndMe hit by network compromise
Initial DisclosureCredential-stuffing attacks against 23andMe stayed undetected for five months, enabling unauthorized access to customer accounts. The compromise ultimately exposed data on 6.9 million customers, including genetic ancestry information.
Show sources
- 23andMe to pay $18 million in new genetics data breach settlement — www.bleepingcomputer.com — 16.07.2026 16:47
- 23andMe to pay $18 million in new genetics data breach settlement — www.bleepingcomputer.com — 16.07.2026 16:47