Breach taxonomy
Summary
23andMe disclosed via Reg FD (Item 7.01) on October 10, 2023 that a threat actor accessed customer profile information shared via the DNA Relatives feature on 23andMe.com. The company believes the actor used credentials reused from other sites that had been previously compromised (credential stuffing) — 23andMe states it has no indication that its own systems suffered a breach or that 23andMe was the source of the credentials. The company activated its IRP, retained third-party forensic experts, and is cooperating with federal law enforcement. Filing did not provide a specific incident date; defaulted to first of October 2023 per workflow rule.
Tagging rationale
ThreatUnknown
Filing uses 'threat actor' generically without attributing to any specific category (cyber-criminals, nation-state, insider, etc.); per taxonomy guide, do not infer actor type from method → UNKNOWN.
MethodsAccount TakeoverCred Stuffing
Filing explicitly describes credentials reused from other previously-compromised websites being used to access 23andMe accounts → CRED-STUFFING. The accounts were taken over via these reused credentials → ACCOUNT-TAKEOVER. 23andMe states its own systems were not breached.
AssetsPersonal Data
Filing states profile information shared via the DNA Relatives feature was accessed from individual customer accounts → PERSONAL-DATA (sensitive genetic-context profile data).
EffectsInfo Privacy Loss
Customer profile information (DNA Relatives data) was accessed without authorization → INFO-PRIVACY-LOSS. No operational disruption disclosed.
Business continuityEffective
Filing states 23andMe 'undertook immediate action in accordance with its incident response plan' with no operational disruption — the breach was at the account-credential layer, not the company's infrastructure → Effective.
Impact
Sensitive genetic-context customer profile data accessed across an unspecified number of accounts, scope and consequences explicitly stated as still being determined ('23andMe is unable to predict the costs and magnitude of those consequences'); high-sensitivity data class, regulatory and class-action exposure, but at filing time no quantified financial impact → score 3.
InsuranceNot disclosed
Filing makes no mention of cyber insurance or insurance proceeds → null.
Read the original SEC filing excerpt
Item 7.01 Regulation FD Disclosure. 23andMe Holding Co. recently learned that certain profile information, which a customer creates and chooses to share with their genetic relatives in the DNA Relatives feature, was accessed from individual 23andMe.com accounts without the account users’ authorization (the 'incident'). Based on 23andMe’s investigation as of the date of this Current Report on Form 8-K, we do not have any indication at this time that there has been a data security incident within our systems, or that 23andMe was the source of the account credentials used in these attacks. While our investigation is ongoing, as of the date of this Current Report on Form 8-K, we believe the threat actor was able to access certain accounts in instances usernames and passwords that were used on 23andMe.com were the same as those used on other websites that had been previously compromised or otherwise available. 23andMe undertook immediate action in accordance with its incident response plan, including taking affirmative security measures to mitigate any potential impact of the incident, working to validate whether data that was accessed was legitimate data from the Website, and determining the full scope of data accessed by unauthorized individuals. 23andMe has retained third-party forensic experts to assist in an investigation of the cause and scope of the incident, and in mitigating and remediating the impact of the incident. 23andMe is fully cooperating with federal law enforcement in relation to this incident.