01Summary
The breach, disclosed on October 6, 2023, involved the theft of a database containing approximately 6.9 million user profiles. The threat actor, identifying as 'Golem,' marketed the data on underground forums, specifically targeting ethnic groups such as Ashkenazi Jews and Chinese users. The methodology employed was a combination of credential stuffing, compromising around 14,000 accounts via reused passwords, followed by scraping the platform's 'DNA Relatives' feature. This scraping allowed the attackers to harvest the genetic data of millions of connected relatives who had not been directly compromised. The exposed fields included display names, sex, birth years, detailed haplogroups (both maternal and paternal), and precise ancestry percentages, making the data highly valuable for identity theft, discrimination, and targeted profiling.
02Background
Genetic testing services like 23andMe have become increasingly popular, generating vast amounts of highly sensitive biometric and health data. This data is unique because, unlike passwords or credit card numbers, it cannot be changed, making any breach permanent and potentially catastrophic for the individual.
03Key revelations
- 01The dataset was segregated by ethnicity, specifically highlighting groups like Ashkenazi Jews and Chinese users.
- 02The breach demonstrated the vulnerability of relational data features (DNA Relatives) to mass scraping.
- 03The exposed data included highly specific genetic markers (haplogroups) and detailed ancestry percentages.
04Technical analysis
The primary attack vector was credential stuffing, exploiting the common practice of users reusing passwords across multiple services. Once initial access was gained to a subset of accounts, the attackers utilized scraping techniques against the platform's relational features (like 'DNA Relatives') to systematically harvest data from connected users, bypassing the need to compromise every single account directly.
- Attack vector
- Credential Stuffing / Password Reuse
- Attack method
- Scraping and Data Exfiltration
- Initial access
- Credential Stuffing
- Lateral movement
- Scraping/API Abuse
- Exfiltration
- Bulk Download/Data Dump
- Malware type
- Stealer/Exfiltration
Vulnerabilities exploited
- Weak Password Practices
- Credential Reuse
MITRE ATT&CK techniques
- T1113
- T1598
05Threat actor
The threat actor 'Golem' operated as a data broker, specializing in high-value, sensitive datasets. Their methodology suggests a focus on exploiting systemic weaknesses (like password reuse) rather than zero-day vulnerabilities, indicating a financially motivated, opportunistic criminal group.
Aliases
- Unknown Threat Actor
MITRE groups
- T1113
Attribution sources
- BreachForums
06Victims and impact
Countries affected
- United States
- Israel
- China
07Data exposed
Data types
- PII
- Genetic Data
- Health Records
- Ancestry Data
Notable documents
- ashkenazi_dna_celebrities.csv
- chinese_user_data.csv
08Financial damage
Estimated damage is in the millions due to potential identity theft, discrimination, and loss of trust in the genetic industry.
09Timeline
- 2023-10-01Initial compromise and data exfiltration begins.
- 2023-10-06Data leak is publicly disclosed on underground forums.
10On the record
You can change your password. You can change your credit card. You cannot change your DNA.
11Reaction and fallout
Public reaction
The public reaction was characterized by alarm regarding the permanence of genetic data and the potential for discrimination. Experts warned that this type of leak could lead to insurance discrimination or targeted profiling.
Political impact
The incident increased regulatory scrutiny globally regarding the storage, sharing, and monetization of genetic information, particularly concerning consumer data privacy.
Geopolitical consequences
The targeting of specific ethnic groups (e.g., Ashkenazi Jews) suggests potential geopolitical or discriminatory motives, raising concerns about targeted surveillance and profiling based on ancestry.
12Legal
While no immediate legal action was reported, the breach intensified calls for stricter global regulations, such as amendments to GDPR or the creation of specific genetic data privacy laws.
Civil lawsuits
- Class-action lawsuits related to data privacy and security failures (anticipated)
13Aftermath
Policy changes
- Increased calls for global regulation of genetic data storage and usage.
Regulatory changes
- Potential amendments to existing privacy laws (e.g., HIPAA, GDPR) to specifically address genetic data.
Security improvements
- Mandatory implementation of multi-factor authentication (MFA) for all user accounts.
- Enhanced internal monitoring to detect large-scale scraping activity.
14Significance and legacy
Significance
This breach is significant because it represents a major failure in protecting 'unchangeable' personal data. It set a precedent for the high value of genetic information in the black market, forcing the industry to confront the unique privacy risks associated with biological data.
Legacy
The incident has accelerated the conversation around 'genetic rights' and data ownership. It is expected to drive the development of specialized cryptographic and legal frameworks designed to protect genomic sequences from unauthorized access and misuse.
15Disclosure and media
- Authentication
- Public Leak/Forum Posting
Media partners
- BreachForums
Publishing organisations
- BreachForums
16Field notes
- 01The attacker specifically segregated the data by ethnicity, suggesting a potential motive beyond simple financial gain.
- 02The use of the 'DNA Relatives' feature as a scraping target highlights the vulnerability of interconnected user data models.
17Resolution
The data was leaked and sold, but the immediate threat was contained by the public disclosure and subsequent industry warnings. 23andMe has since issued security advisories.
18Sources
References
- [1]BreachForums Leak
- [2]23andMe Security Advisories









