Jon Styf , Abraham Jewett  |  January 9, 2024

Category: Data Breach
Close up of 23 and Me signage, representing the 23andMe data breach.
(Photo Credit: Lets Design Studio/Shutterstock)

Update:

  • 23andMe reportedly blamed an October 2023 data breach on its customers’ failure to update their passwords for the genetic testing service. 
  • The company faces more than 30 complaints in the wake of the data breach, which it confirmed compromised the data of nearly 6.9 million of its users.
  • In a letter sent to a group of hundreds of victims addressed Dec. 11 and obtained by TechCrunch, 23andMe argues the incident was not a result of it failing to maintain reasonable security measures.
  • 23andMe told the users they should have updated their passwords following previous security breaches of other websites that used the same login credentials.

23andMe data breach overview: 

  • Who: 23andMe has confirmed a data breach that affected 6.9 million users. 
  • Why: The 23andMe data breach included a variety of account access, including credential stuffing to log in to 0.1% of accounts and access to some data through the DNA Relatives feature, the website reported.
  • Where: The 23andMe breach affected accounts across the world.

(Dec. 11, 2023)

23andMe has confirmed a data breach that happened Oct. 10 and affected 6.9 million users, according to Law360.com.

Hackers reportedly accessed 0.1% of accounts using credential stuffing with login data used on other websites that had been previously compromised or were otherwise available, according to an amended filing the company made with the U.S. Securities and Exchange Commission (SEC).

“The threat actor also accessed roughly 5.5 million DNA Relatives profile files,” a company spokesperson said in a statement to Law360 on Dec. 5. “Additionally, roughly 1.4 [million] customers participating in the DNA Relatives feature had their Family Tree profile information accessed, which is a limited subset of the DNA Relative profile information.”

The data accessed in the 23andMe breach varied by user account but generally included ancestry information and, for some, health-related information based on a user’s genetics, the SEC filing said.

The company found out about the data breach after users claimed online that they had accessed the data and were attempting to sell the 23andMe hack information.

23andMe hack costs are $1 million to $2 million with undetermined future expenses

23andMe says it expects to incur between $1 million and $2 million in expenses related to the data breach in the fiscal third quarter that ends Dec. 31.

The company said it is facing class action lawsuits in both federal and state courts, including state court filings in California and Illinois as well as in British Columbia and Ontario, Canada.

23andMe said in the SEC filing that it is too early in the process to assess how the class action lawsuits will finish, what the costs associated with the lawsuits will include and what portion of expenses from the lawsuits will be covered by insurance.

The company also is still determining how it will respond to notices filed by consumers under the California Consumer Privacy Act and to inquiries from various governmental officials and agencies.

Was your data accessed in the 23andMe hack? Let us know in the comments.


Don’t Miss Out!

Check out our list of Class Action Lawsuits and Class Action Settlements you may qualify to join!


Read About More Class Action Lawsuits & Class Action Settlements:

We tell you about cash you can claim EVERY WEEK! Sign up for our free newsletter.

112 thoughts on23andMe reportedly blames data breach on victims

  1. Dianna says:

    I have used this service before.

  2. mary ballerin says:

    I was an early 23andme user and I used the most secure password of my life when I made that acct online. Keep adding this Illinoisan please.

  3. Christy Jaros says:

    Add me

  4. Greg says:

    Yes affected by data breach

1 9 10 11

Leave a Reply

Your email address will not be published. By submitting your comment and contact information, you agree to receive marketing emails from Top Class Actions regarding this and/or similar lawsuits or settlements, and/or to be contacted by an attorney or law firm to discuss the details of your potential case at no charge to you if you qualify. Required fields are marked *

Please note: Top Class Actions is not a settlement administrator or law firm. Top Class Actions is a legal news source that reports on class action lawsuits, class action settlements, drug injury lawsuits and product liability lawsuits. Top Class Actions does not process claims and we cannot advise you on the status of any class action settlement claim. You must contact the settlement administrator or your attorney for any updates regarding your claim status, claim form or questions about when payments are expected to be mailed out.