Skip to main content
23andMe Breach: What Happened and How to Protect Your DNA Data — illustration

23andMe Breach: What Happened and How to Protect Your DNA Data

In October 2023, a credential-stuffing attack on 23andMe exposed the personal and genetic data of 6.9 million people. Here's the full timeline, what was stolen, and practical steps you can take right now to protect your DNA data.

By Peter Hollens·Last updated: ·10 min read

Key Takeaways

  • In October 2023, hackers used credential stuffing to breach 14,000 23andMe accounts and scraped genetic data from 6.9 million users via the DNA Relatives feature
  • Exposed data included ancestry composition, predicted relationships, birth years, and locations — information that is permanent and cannot be reset like a password
  • A $50 million class-action settlement received final court approval in January 2026, but payouts of $100-$165 per person barely cover credit monitoring
  • 23andMe filed for bankruptcy in March 2025 and was acquired by TTAM Research Institute in July 2025 — download your data and consider deleting your account
  • DNA Explore was built as a direct response to the breach: your genetic data never leaves your device, eliminating server-side breach risk entirely
“I signed up for 23andMe in 2017 because I was fascinated by what my DNA could tell me. Six years later, my data was compromised in their breach — I'm a confirmed class member in the litigation. I didn't want to hand my genetic data to another company, so I built a tool where everything stays on your device. Then I thought: why not give people what I was actually searching for when I got my DNA tested in the first place — actionable health insights, drug metabolism analysis, risk scores — things you can actually do something with.”

Peter Hollens

Founder, DNA Explore · Wikipedia

Timeline of the 23andMe Data Breach

How the Attack Started: Credential Stuffing

The 23andMe data breach began in October 2023, when hackers used a technique called credential stuffing to access approximately 14,000 user accounts. Credential stuffing works by taking username-and-password combinations leaked from other breaches and trying them against a new service. Because many people reuse passwords across sites, the attackers were able to log in to thousands of 23andMe accounts without breaking any encryption.

How DNA Relatives Multiplied the Damage

But the damage did not stop at those 14,000 accounts. Once inside, the attackers exploited the DNA Relatives feature, a social tool that lets users discover and connect with genetic matches. Through that feature, the hackers scraped profile data from roughly 6.9 million additional users — approximately 5.5 million through DNA Relatives profiles and approximately 1.4 million through Family Tree profiles.

Public Disclosure and Full Scope

The stolen data first appeared on BreachForums on October 1, 2023, posted by a threat actor using the handle 'Golem,' initially targeting people of Ashkenazi Jewish and Chinese descent. 23andMe disclosed the breach publicly on October 6, 2023, and over the following weeks the full scope became clear. On December 1, 2023, the company confirmed the 6.9 million figure in an SEC filing. The breach became one of the largest exposures of genetic data in history, and it raised fundamental questions about whether consumer genomics companies can be trusted to safeguard the most personal information imaginable: your DNA.

What Data Was Exposed in the 23andMe Breach

Directly Compromised Accounts

The 23andMe data breach exposed several categories of sensitive personal and genetic information. For the approximately 14,000 directly compromised accounts, the attackers had full access to everything in those profiles, including:
  • Raw genotype data
  • Ancestry composition reports
  • Health predisposition reports
  • Account details

Data Scraped via DNA Relatives

For the 6.9 million users scraped through DNA Relatives, the exposed data included display names, birth years, ancestry composition percentages, predicted relationships to other users, geographic locations, and in some cases family surnames and profile photos. While full raw DNA files were not scraped for this larger group, the ancestry and relationship data is deeply revealing. Knowing someone's precise ethnic background, their birth year, their location, and their genetic relatives creates a detailed identity profile. This data cannot be changed like a credit card number. Your ancestry composition and DNA relative connections are permanent.

Family Network Exposure

The breach also exposed the structure of family networks. Attackers could map out who is related to whom, reconstruct family trees, and potentially identify individuals even if they never used 23andMe themselves. For adoptees, donor-conceived individuals, or anyone with sensitive family circumstances, this kind of exposure can have life-altering consequences that go far beyond typical data breaches.

The $50 Million Settlement and Its Aftermath

Terms of the Class-Action Settlement

In September 2024, 23andMe agreed to an initial $30 million class-action settlement. Following the company's March 2025 bankruptcy filing, the settlement was revised upward to $50 million and received final court approval on January 20, 2026. The settlement covered all U.S. users whose data was exposed, and it required 23andMe to implement stronger security measures including mandatory two-factor authentication and regular third-party security audits.

What $50 Million Actually Means Per Person

On paper, $50 million sounds significant. In practice, payouts are tiered: eligible claimants can receive between $100 and $165 depending on the type of data exposed, with documented extraordinary losses eligible for up to $10,000. For the majority of the 6.9 million affected users, the payout barely covers a credit monitoring subscription.

Why Legal Frameworks Fall Short for DNA

The settlement also highlighted how poorly existing legal frameworks handle genetic data breaches. Unlike financial data, DNA cannot be reissued. There is no equivalent of freezing your credit or getting a new account number. Once your ancestry composition and relative connections are in the hands of bad actors, that information is out there permanently. The settlement required 23andMe to delete genetic data for inactive accounts after a set period, but for the millions of users whose data was already scraped and posted on hacking forums, the damage was already done. The payout felt more like a symbolic gesture than a meaningful remedy for what many consider the most personal data breach in consumer technology history.

23andMe Bankruptcy: What Happened to Your DNA

The Chapter 11 Filing

In March 2025, 23andMe filed for Chapter 11 bankruptcy protection. The company had been struggling financially for years, with its stock price down more than 98 percent from its peak after going public through a SPAC deal in 2021. The breach accelerated the decline in consumer trust, and the company's attempts to pivot into drug development did not generate enough revenue to offset the losses.

The Bidding Process and Acquisition

The bankruptcy filing raised an urgent question: what happens to the genetic data of roughly 15 million customers when the company is sold? Multiple bidders expressed interest, including pharmaceutical company Regeneron. Privacy advocates, attorneys general, and members of Congress raised alarms. The California Attorney General issued a public warning encouraging 23andMe users to download their data and delete their accounts before a sale. In July 2025, TTAM Research Institute — a nonprofit founded by 23andMe co-founder Anne Wojcicki — acquired the company for $305 million.

What the TTAM Acquisition Means for Your Data

TTAM committed to maintaining 23andMe's existing privacy policies and established a consumer-privacy advisory board. However, your data is now held by a different legal entity than the one you originally consented to. The structural risk remains: if TTAM's ownership changes in the future, the cycle of uncertainty around your genetic data repeats. DNA data stored under any organization is subject to the corporate lifecycle — acquisitions, policy changes, and future breaches are always possible.

How to Protect Your DNA Data Right Now

If you have ever used 23andMe, there are immediate steps you should take to protect your DNA data.

Step 1: Download Your Raw Data

Log into your 23andMe account and download your raw data file. Go to Settings, then scroll to 23andMe Data, and request a download. This gives you a local copy of your genotype data that you can use with third-party analysis tools without relying on 23andMe to remain operational.

Step 2: Opt Out of DNA Relatives

Opt out of DNA Relatives if you have not already. This was the feature the hackers exploited to scrape 6.9 million profiles. Navigate to Settings, then DNA Relatives, and revoke your consent.

Step 3: Delete Your Account

Consider deleting your 23andMe account entirely. Go to Settings, then 23andMe Data, and select the option to permanently delete your data. The company — now operating under TTAM Research Institute following the July 2025 acquisition — is required to destroy your genetic sample and remove your data from their systems, though the process can take several weeks.

Step 4: Secure Your Other Accounts

Check whether your email address was part of the breach using haveibeenpwned.com, and change your password on any service where you used the same credentials. Enable two-factor authentication everywhere you can.

Step 5: Use a Privacy-First Analysis Tool

If you still want to explore your genetic data, use a privacy-first analysis tool that does not require uploading your DNA file to anyone's servers. This is the single most effective way to protect your DNA going forward: keep your data on your own device.

Why Peter Hollens Built DNA Explore After the Breach

A Personal Experience with the Breach

DNA Explore exists because of the 23andMe breach. Founder Peter Hollens was among the millions of users whose data was exposed in the October 2023 attack. Like millions of others, he had trusted 23andMe with his raw DNA data and used the DNA Relatives feature to explore his genetic connections. When the breach happened, he realized there was no way to undo the exposure, and the experience fundamentally changed how he thought about genetic privacy.

Privacy as an Architectural Guarantee

Peter had already been exploring ways to make consumer genomics more accessible, but the breach crystallized the mission: build a DNA analysis tool where the data never leaves the user's device. Not as a marketing claim, but as an architectural guarantee. DNA Explore processes your raw DNA file entirely in your browser using client-side JavaScript. There is no upload endpoint, no server-side storage, no database of genetic data that can be breached, subpoenaed, or sold in a bankruptcy proceeding. The analysis runs locally on your machine and the results stay on your machine.

Building What Should Have Existed All Along

It is an approach we believe should be the standard for consumer genomics. After watching 23andMe go through bankruptcy and knowing that the genetic data of millions — including his own — had been posted on hacking forums, Peter built the tool he wished had existed before he ever uploaded his DNA to a corporate server.

DNA Explore: Analyze Your DNA Without Uploading It Anywhere

How It Works

DNA Explore is a browser-based genetic analysis tool built on a privacy-first architecture. You drag and drop your raw DNA file from 23andMe or AncestryDNA into the app, and everything is processed locally in your browser. Your genome data never touches a server. There is no account to create, no cloud storage, and no third party that ever sees your file.

What the Analysis Covers

The analysis covers:
  • Health predispositions
  • Pharmacogenomics for understanding how you metabolize common medications
  • Nutrigenomics for diet and supplement recommendations based on your genetic profile
  • Polygenic risk scores that combine hundreds of variants into meaningful risk estimates
  • Gene-gene interactions that reveal how your variants work together
These reports are for informational and educational purposes only and do not replace consultation with a qualified healthcare provider. An AI-powered chat feature lets you ask questions about your results in plain language.

Simple, One-Time Pricing

DNA Explore costs $9.99 as a one-time payment. There is no subscription, no upselling, and no recurring fees. You get a free preview of a subset of your results before paying, so you can evaluate the tool with your own data before committing. In a post-breach world where 23andMe is bankrupt and genetic data has proven to be a high-value target, the safest way to analyze your DNA is to never let it leave your device. That is exactly what DNA Explore was designed to do.

The Future of Genetic Privacy After the 23andMe Breach

A Turning Point for Consumer Genomics

The 23andMe data breach marked a turning point for consumer genomics. For years, the industry operated on the assumption that people would willingly trade their most personal data for ancestry pie charts and health reports. The breach, the settlement, and the bankruptcy shattered that assumption. Consumer trust in centralized genetic databases is at an all-time low, and it may never fully recover.

The Regulatory Landscape

Regulatory responses are emerging but remain slow. Some states have introduced genetic privacy bills, and there is growing pressure on Congress to pass federal legislation specifically protecting DNA data. The European Union's GDPR already treats genetic data as a special category, but enforcement has been inconsistent.

Architecture Over Legislation

In the meantime, the most effective protection is architectural, not legal. If a company never has your data, it cannot breach it, sell it, or hand it over in bankruptcy. This is the principle behind privacy-by-design, and it is the foundation of tools like DNA Explore.

The Real Lesson of the Breach

The lesson of the 23andMe breach is not that genetic testing is dangerous. Understanding your DNA can be genuinely valuable for health decisions, medication choices, and personal knowledge. The lesson is that uploading your DNA to a corporate server creates a permanent risk that no privacy policy, security audit, or class-action settlement can fully mitigate. The technology to analyze DNA locally already exists. The question is whether consumers will demand it. To explore your options, see our guide to the cheapest DNA testing in 2026.

Frequently Asked Questions

What happened in the 23andMe data breach?
In October 2023, hackers used credential stuffing to access approximately 14,000 23andMe accounts. They then exploited the DNA Relatives feature to scrape personal and genetic data from 6.9 million additional users. Exposed data included display names, birth years, ancestry composition, predicted relationships, and geographic locations. The breach became one of the largest genetic data exposures in history.
How do I delete my 23andMe data after the breach?
Log into your 23andMe account, go to Settings, then 23andMe Data, and select the option to permanently delete your data. Before deleting, download your raw data file first so you still have access to your genetic information. After requesting deletion, 23andMe is required to destroy your saliva sample and remove your data from their servers within several weeks.
Is my DNA data safe after the 23andMe bankruptcy?
In July 2025, TTAM Research Institute — a nonprofit founded by Anne Wojcicki — acquired 23andMe for $305 million. TTAM has committed to maintaining existing privacy policies and established a consumer-privacy advisory board. However, your data has been transferred to a new legal entity. If you still have a 23andMe account, the safest step is to download your raw data and then delete your account, since future ownership changes could put your data at risk again.
How can I analyze my DNA without uploading it to a server?
DNA Explore processes your raw DNA file entirely in your browser. You drag and drop your 23andMe or AncestryDNA file into the app, and the analysis runs locally on your device. Your genetic data never leaves your machine. There is no account, no cloud storage, and no upload. It costs $9.99 one-time with no subscription required.
What is credential stuffing and how did it affect 23andMe users?
Credential stuffing is a hacking technique where attackers use username-and-password combinations leaked from other data breaches to try logging into a different service. Because many people reuse passwords, the attackers gained access to approximately 14,000 23andMe accounts. From there, the DNA Relatives feature allowed them to scrape data from 6.9 million connected profiles, multiplying the impact far beyond the initially compromised accounts.

Sources & References

  1. Wikipedia — 23andMe Data Breach
  2. 23andMe Data Breach Class Action Settlement
  3. DNA Explore Privacy Policy

Disclaimer: The information provided in this article is for general educational and informational purposes only and does not constitute medical, legal, or financial advice. Genetic information should not be used as a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider before making any health decisions based on genetic data.

Prices, features, and availability of third-party products and services mentioned in this article are based on publicly available information as of the publication date and may have changed. We make reasonable efforts to ensure accuracy but cannot guarantee that all pricing, feature descriptions, or company information is current or complete. Trademarks and brand names referenced are the property of their respective owners and are used solely for identification and comparison purposes.

Genetic risk assessments, polygenic risk scores, and pharmacogenomic reports generated by any consumer tool — including DNA Explore — are based on currently published research and known associations. They are not diagnostic. Genetic predisposition does not guarantee the development or absence of any condition.

See what your DNA says about you

Drop your 23andMe or AncestryDNA file. Results in seconds. $9.99 to unlock everything.

Try DNA Explore free

Already purchased? Restore your access