Security

23andMe confirms hackers stole ancestry data on 6.9 million users

Comment

a sign outside 23andMe's office in California, featuring the company's office in the background
Image Credits: David Paul Morris / Bloomberg / Getty Images

On Friday, genetic testing company 23andMe announced that hackers accessed the personal data of 0.1% of customers, or about 14,000 individuals. The company also said that by accessing those accounts, hackers were also able to access “a significant number of files containing profile information about other users’ ancestry.” But 23andMe would not say how many “other users” were impacted by the breach that the company initially disclosed in early October.

As it turns out, there were a lot of “other users” who were victims of this data breach: 6.9 million affected individuals in total.

In an email sent to TechCrunch late on Saturday, 23andMe spokesperson Katie Watson confirmed that hackers accessed the personal information of about 5.5 million people who opted-in to 23andMe’s DNA Relatives feature, which allows customers to automatically share some of their data with others. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location.

23andMe also confirmed that another group of about 1.4 million people who opted-in to DNA Relatives also “had their Family Tree profile information accessed,” which includes display names, relationship labels, birth year, self-reported location and whether the user decided to share their information, the spokesperson said. (23andMe declared part of its email as “on background,” which requires that both parties agree to the terms in advance. TechCrunch is printing the reply as we were given no opportunity to reject the terms.)

It is also not known why 23andMe did not share these numbers in its disclosure on Friday.

Considering the new numbers, in reality, the data breach is known to affect roughly half of 23andMe’s total reported 14 million customers.

In early October, a hacker claimed to have stolen the DNA information of 23andMe users in a post on a well-known hacking forum. As proof of the breach, the hacker published the alleged data of one million users of Jewish Ashkenazi descent and 100,000 Chinese users, asking would-be buyers for $1 to $10 for the data per individual account. Two weeks later, the same hacker advertised the alleged records of another four million people on the same hacking forum.

TechCrunch found that another hacker on a separate hacking forum had already advertised a batch of allegedly stolen 23andMe customer data two months before the widely reported advertisement.

Contact Us

Do you have more information about the 23andMe incident? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email lorenzo@techcrunch.com. You also can contact TechCrunch via SecureDrop.

When we analyzed the months-old leaked data, TechCrunch found that some records matched genetic data published online by hobbyists and genealogists. The two sets of information were formatted differently, but contained some of the same unique user and generic data, suggesting the data leaked by the hacker was at least in part authentic 23andMe customer data.

In disclosing the incident in October, 23andMe said the data breach was caused by customers reusing passwords, which allowed hackers to brute-force the victims’ accounts by using publicly known passwords released in other companies’ data breaches.

Because of the way that the DNA Relatives feature matches users with their relatives, by hacking into one individual account, the hackers were able to see the personal data of both the account holder as well as their relatives, which magnified the total number of 23andMe victims.

Read more on TechCrunch:

More TechCrunch

The U.K.’s antitrust regulator has delivered its provisional ruling in a longstanding battle to combine two of the country’s major telecommunication operators. The Competition and Markets Authority (CMA) says that…

Three and Vodafone’s $19B merger hits the skids as UK rules the deal would adversely impact customers and MVNOs

Late Thursday evening, Oprah Winfrey aired a special on AI, appropriately titled “AI and the Future of Us.” Guests included OpenAI CEO Sam Altman, tech influencer Marques Brownlee, and current…

Oprah just had an AI special with Sam Altman and Bill Gates — here are the highlights

Antonio Moraes, the grandson of a late prominent Brazilian billionaire, was never interested in joining the family-owned conglomerate of construction companies and a bank. Shortly after graduating from college, he…

XP Health grabs $32M to bring employees more affordable vision care

A crew of four private astronauts made history in the early hours of Thursday when they opened the hatch of their SpaceX Dragon capsule and conducted the first commercial spacewalk. …

Polaris Dawn astronauts perform historic private spacewalk while wearing SpaceX-made suits

Keith Rabois, managing director of Khosla Ventures, was having dinner with a “very successful CEO” in October 2018 when the CEO asked him a question: How many people does it…

Keith Rabois says Miami is still a great place for startups, even as a16z leaves

By making the AI info label harder to find, it might be easier for users to be deceived by content that was edited with AI, especially as editing tools become…

Meta is making its AI info label less visible on content edited or modified by AI tools

Cohost, a would-be X rival launched to the public in June 2022, is shutting down, the company announced via the social network’s staff account earlier this week. The service had…

Cohost, the X rival founded with an anti-Big Tech manifesto, is running out of money and will shut down

At the MTV Video Music Awards (VMAs) on Wednesday night, new technology allowed fans to shop their favorite artists’ styles as they appeared on the screen. Though the drama from…

Shopsense AI lets music fans buy dupes inspired by red-carpet looks at the VMAs

Featured Article

A comprehensive list of 2024 tech layoffs

A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024.

A comprehensive list of 2024 tech layoffs

Working away on his PhD in Munich only a few years ago, Stephan Herrmann (now a doctor) couldn’t have conceived of a time when his idea for a carbon-negative power…

This startup is making manure out of other biogas power plants and now has $62M to play with

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm since its launch in November 2022. What started as a tool to hyper-charge productivity through writing essays and code…

ChatGPT: Everything you need to know about the AI-powered chatbot

Faraday Future is doling out big raises and bonuses to its CEO and its founder, despite having delivered just 13 cars in its 10-year history and recently laying off or…

Faraday Future gives CEO and founder raises and bonuses after delivering 13 cars

We’re out-of-this-world excited to announce that we’ve finalized our dedicated Space Stage at TechCrunch Disrupt 2024. It joins Fintech, SaaS and AI as the other industry-focused stages — all under…

Announcing the final agenda for the Space Stage at TechCrunch Disrupt 2024

Online sports apparel retailer Fanatics has agreed to settle and drop a lawsuit that it filed against troubled one-click payments provider Bolt in March, according to court documents obtained by…

Bolt has quietly settled its lawsuit with Fanatics amid ongoing boardroom drama

Rajeev Behera’s new all-on-one HR startup, dubbed Every, is either brilliant or crazy.

Why Y Combinator companies are flocking to banking and HR startup Every

It’s a small advance, but one that speaks to Meta’s enginerring team paying attention to how the fediverse community is trying to educate Threads users about the possibilities.  

Threads makes it easier to evangelize the open social web with a new direct link feature

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! The transportation…

Autonomous delivery startup Nuro pivots and another Indian EV scooter startup takes the IPO road

ChatGPT maker OpenAI has announced a model that can effectively fact-check itself by “reasoning” through questions.

OpenAI unveils o1, a model that can fact-check itself

The Australian government wants to fine social media platforms up to 5% of their global revenue if they fail to stop the spread of misinformation under a revised legislative plan…

Australian plan for misinformation law riles Elon Musk

An Indian antitrust regulator has found that Amazon and Flipkart, owned by Walmart, violated local competition laws, according to a report from Reuters. The finding presents a new challenge for…

Amazon and Flipkart violated competition laws in India, report says

Tune.FM is a decentralized music streaming service where users pay for each song they stream using Tune.FM’s crypto token JAM.

Tune.FM wants to take on Spotify by using crypto to pay artists up to 100x more per stream

DeepMind employed a new learning platform, ALOHA Unleashed, paired with its simulation program, DemoStart, to teach robots by watching humans.

Google DeepMind teaches a robot to autonomously tie its shoes and fix fellow robots

The FDA on Thursday announced that it has granted what it calls “the first over-the-counter (OTC) hearing aid software device, Hearing Aid Feature.”

Apple AirPods Pro granted FDA approval to serve as hearing aids

Google announced on Thursday that it’s introducing new Wallet updates for travelers and commuters. Most notably, Google Wallet will soon start beta testing the ability to create a Digital ID…

Google Wallet to test a feature that turns your US passport into a digital ID

The White House says several major AI vendors have committed to taking steps to combat nonconsensual deepfakes and child sexual abuse material. Adobe, Cohere, Microsoft, Anthropic OpenAI, and data provider…

White House extracts voluntary commitments from AI vendors to combat deepfake nudes

Microsoft is laying off around 650 employees from its gaming division, according to an internal memo shared online by IGN. The latest cuts come eight months after the company laid…

Microsoft lays off another 650 from gaming division

Featured Article

Hacker tricks ChatGPT into giving out detailed instructions for making homemade bombs

An explosives expert told TechCrunch that the ChatGPT output could be used to make a detonatable product and was too sensitive to be released.

Hacker tricks ChatGPT into giving out detailed instructions for making homemade bombs

In an attempt to prevent suicide and self-harm content from spreading online, the nonprofit Mental Health Coalition (MHC) today announced a new program, Thrive, aimed at encouraging online platforms to…

Meta, TikTok, and Snap pledge to participate in program to combat suicide and self-harm content

The U.K. government has introduced a new bill to Parliament which proposes new legal protections for digital assets such as Bitcoin.

Bitcoin and NFTs may get greater legal protections as ‘personal property’ under proposed UK law

Elon Musk’s social network X is exploring a new feature that would allow users to block others from direct messaging them, but in a way that’s separate from the account…

X is working on a new way for people to block DMs