EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/23andme-genetic-data-breach-2023
126/430

File EL-0305CriticalResolvedData Breach / Genetic Data Exfiltration

23andMe Genetic Data Breach

Also filed as DNA Relatives Database Leak · Ashkenazi DNA Leak

This incident involved the unauthorized exfiltration and public sale of a massive dataset containing genetic and personal information from 23andMe users. The leaked data included detailed ancestry breakdowns, haplogroups, and predicted familial relationships. The breach highlighted the extreme sensitivity and permanence of genetic data.

  • #genetic-data
  • #pii
  • #dna
  • #credential-stuffing
  • #data-leak
  • #health-data
Notoriety8/10
Event
1 Oct 2023
Disclosed
6 Oct 2023
Target
23andMe
Actor
Golem
Scale
6.9M people
Status
Resolved

01Summary

The breach, disclosed on October 6, 2023, involved the theft of a database containing approximately 6.9 million user profiles. The threat actor, identifying as 'Golem,' marketed the data on underground forums, specifically targeting ethnic groups such as Ashkenazi Jews and Chinese users. The methodology employed was a combination of credential stuffing, compromising around 14,000 accounts via reused passwords, followed by scraping the platform's 'DNA Relatives' feature. This scraping allowed the attackers to harvest the genetic data of millions of connected relatives who had not been directly compromised. The exposed fields included display names, sex, birth years, detailed haplogroups (both maternal and paternal), and precise ancestry percentages, making the data highly valuable for identity theft, discrimination, and targeted profiling.

02Background

Genetic testing services like 23andMe have become increasingly popular, generating vast amounts of highly sensitive biometric and health data. This data is unique because, unlike passwords or credit card numbers, it cannot be changed, making any breach permanent and potentially catastrophic for the individual.

03Key revelations

  1. 01The dataset was segregated by ethnicity, specifically highlighting groups like Ashkenazi Jews and Chinese users.
  2. 02The breach demonstrated the vulnerability of relational data features (DNA Relatives) to mass scraping.
  3. 03The exposed data included highly specific genetic markers (haplogroups) and detailed ancestry percentages.

04Technical analysis

The primary attack vector was credential stuffing, exploiting the common practice of users reusing passwords across multiple services. Once initial access was gained to a subset of accounts, the attackers utilized scraping techniques against the platform's relational features (like 'DNA Relatives') to systematically harvest data from connected users, bypassing the need to compromise every single account directly.

Attack vector
Credential Stuffing / Password Reuse
Attack method
Scraping and Data Exfiltration
Initial access
Credential Stuffing
Lateral movement
Scraping/API Abuse
Exfiltration
Bulk Download/Data Dump
Malware type
Stealer/Exfiltration

Vulnerabilities exploited

  • Weak Password Practices
  • Credential Reuse

MITRE ATT&CK techniques

  • T1113
  • T1598

05Threat actor

The threat actor 'Golem' operated as a data broker, specializing in high-value, sensitive datasets. Their methodology suggests a focus on exploiting systemic weaknesses (like password reuse) rather than zero-day vulnerabilities, indicating a financially motivated, opportunistic criminal group.

Aliases

  • Unknown Threat Actor

MITRE groups

  • T1113

Attribution sources

  • BreachForums

06Victims and impact

Countries affected

  • United States
  • Israel
  • China

07Data exposed

Data types

  • PII
  • Genetic Data
  • Health Records
  • Ancestry Data

Notable documents

  • ashkenazi_dna_celebrities.csv
  • chinese_user_data.csv

08Financial damage

Estimated damage is in the millions due to potential identity theft, discrimination, and loss of trust in the genetic industry.

09Timeline

  1. 2023-10-01Initial compromise and data exfiltration begins.
  2. 2023-10-06Data leak is publicly disclosed on underground forums.

10On the record

You can change your password. You can change your credit card. You cannot change your DNA.

Threat Actor 'Golem', A statement emphasizing the permanence and high value of genetic data.

11Reaction and fallout

Public reaction

The public reaction was characterized by alarm regarding the permanence of genetic data and the potential for discrimination. Experts warned that this type of leak could lead to insurance discrimination or targeted profiling.

Political impact

The incident increased regulatory scrutiny globally regarding the storage, sharing, and monetization of genetic information, particularly concerning consumer data privacy.

Geopolitical consequences

The targeting of specific ethnic groups (e.g., Ashkenazi Jews) suggests potential geopolitical or discriminatory motives, raising concerns about targeted surveillance and profiling based on ancestry.

12Legal

While no immediate legal action was reported, the breach intensified calls for stricter global regulations, such as amendments to GDPR or the creation of specific genetic data privacy laws.

Civil lawsuits

  • Class-action lawsuits related to data privacy and security failures (anticipated)

13Aftermath

Policy changes

  • Increased calls for global regulation of genetic data storage and usage.

Regulatory changes

  • Potential amendments to existing privacy laws (e.g., HIPAA, GDPR) to specifically address genetic data.

Security improvements

  • Mandatory implementation of multi-factor authentication (MFA) for all user accounts.
  • Enhanced internal monitoring to detect large-scale scraping activity.

14Significance and legacy

Significance

This breach is significant because it represents a major failure in protecting 'unchangeable' personal data. It set a precedent for the high value of genetic information in the black market, forcing the industry to confront the unique privacy risks associated with biological data.

Legacy

The incident has accelerated the conversation around 'genetic rights' and data ownership. It is expected to drive the development of specialized cryptographic and legal frameworks designed to protect genomic sequences from unauthorized access and misuse.

15Disclosure and media

Authentication
Public Leak/Forum Posting

Media partners

  • BreachForums

Publishing organisations

  • BreachForums

16Field notes

  1. 01The attacker specifically segregated the data by ethnicity, suggesting a potential motive beyond simple financial gain.
  2. 02The use of the 'DNA Relatives' feature as a scraping target highlights the vulnerability of interconnected user data models.

17Resolution

The data was leaked and sold, but the immediate threat was contained by the public disclosure and subsequent industry warnings. 23andMe has since issued security advisories.

18Sources

References

  1. [1]BreachForums Leak
  2. [2]23andMe Security Advisories
Fact sheetEL-0305

Dates

Event
1 Oct 2023
Started
1 Oct 2023
Ended
6 Oct 2023
Duration
5 days
Discovered
6 Oct 2023
Disclosed
6 Oct 2023
Ongoing
No

Target

Organisation
23andMe
Type
Technology Company
Sector
Genetics/Health
Country
United States

Actor

Name
Golem
Type
Criminal Gang
Motivation
Financial gain through the sale of highly sensitive personal and genetic information.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

People
6,900,000
Records
6,900,000
Volume
6.9 million records
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.