---
title: "Hackers Selling Stolen Customer DNA Data From 23AndMe"
description: "The consumer DNA kit company 23andMe has acknowledged that hackers had gained access to user accounts, but we have lots of questions."
date: "2023-10-12"
modified: "2023-10-12"
authors:
  - name: "Noor Al-Sibai"
    job_title: "Senior Staff Writer"
    link: "https://futurism.com/authors/nooralsibai"
url: "https://futurism.com/neoscope/23andme-hack-dna-data"
categories:
  - "DNA"
  - "Gene Editing"
  - "Genetics"
  - "Health & Medicine"
tags:
  - "23andme"
  - "dna"
  - "dna kits"
  - "hack"
---

# Hackers Selling Stolen Customer DNA Data From 23AndMe

![The consumer DNA kit company 23andMe has acknowledged that hackers had gained access to user accounts, but we have lots of questions.](<https://futurism.com/wp-content/uploads/2023/10/23andme-hack-dna-data.jpg>)
*Could be a computer hacker, a network security analyst, or even code programmer looking into a computer screen of code. \<em\>Image: Daniel Haug via Getty Images\</em\>*

After reports of a massive user data hack [began circulating online](<https://twitter.com/mattjay/status/1710370423311888724>), the consumer DNA sequencing company 23andMe has acknowledged a breach that's seemingly led to its customers' genetic info circulating online.

As [*Bleeping Computer* reported](<https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/>) and [*The Verge* later confirmed](<https://www.theverge.com/2023/10/7/23907330/23andme-leak-hackers-selling-user-dna-data>), an unidentified hacker posted on a data-selling forum that they had access to a million lines of DNA information on the consumer DNA company's users.

Even more darkly, the hackers are specifically offering data on users they say have Ashkenazi Jewish ancestry — even teasing, with no evidence and in starkly anti-semitic terms, that some data belongs to notable public figures.

"On offer are DNA profiles of millions, ranging from the world's top business magnates to dynasties often whispered about in conspiracy theories," one of the posts on the data-selling forum reads. "Each set of data also comes with corresponding email addresses."

23andMe acknowledged to both *Bleeping Computer* and *The Verge* that although user data had been "compiled," the breach did not occur within 23andMe's system, but rather was the product of "recycled login credentials" that had been "leaked during incidents involving other online platforms."

In its [own post about the hack](<https://blog.23andme.com/articles/addressing-data-security-concerns>), 23andMe said that it was investigating the hack that involved "customer profile information" being accessed by bad actors through its DNA Relatives feature, but it did not disclose specifically what type of data had been obtained.

The company also did not say how much data was implicated in the hack. As [*Ars Technica* has reported](<https://arstechnica.com/security/2023/10/private-23andme-user-data-is-up-for-sale-after-online-scraping-spree/>), a post on another crime forum claimed that hackers had obtained "13M pieces of data," though it's likely that that number was inflated to increase the chances of a sale.

Troublingly, this isn't the first time a DNA kit company has suffered a hack.

Back in 2018, hackers gained access to a whopping 92 million accounts on the genealogy and DNA testing company MyHeritage, the [company admitted](<https://blog.myheritage.com/2018/06/myheritage-statement-about-a-cybersecurity-incident/>) at the time. While the information gained in the so-called "cybersecurity incident" didn't go beyond email addresses and passwords, it still represented a blow to the burgeoning industry that asked consumers not just to pay for their DNA to be sequenced, but to trust companies with their sensitive data, too.

The blow, obviously, wasn't enough to stop [tens of millions of people](<https://www.abc.net.au/news/2023-05-13/dna-kit-third-party-access-genetic-data-research/102230764>) from spitting into test tubes and sending their genetic material to companies like 23andMe. Although there are still many outstanding questions about this latest hack, it seems more and more certain that consumer DNA companies [can't be trusted with securely storing](<https://www.theverge.com/2018/6/6/17435166/myheritage-dna-breach-genetic-privacy-bioethics>) their users' data in perpetuity — and that the people who paid them to do so may have made a huge mistake.

**More on DNA:** [*DNA Tests Have a Nasty Side Effect*](<https://futurism.com/neoscope/dna-test-parents-secrets>)

## Author
At Futurism, I've often been drawn to unpacking the narratives that underlie technological, scientific and medical progress, with a special interest in areas of conflict and ambiguity that end up setting agendas and steering the fates of both elites and the hoi polloi. I'm a committed generalist, but I often find myself returning to work involving NASA and the private space sector, the effects of AI on media and society, and the mechanics of the pharmaceutical industry, with a specific focus on the spread of GLP-1 drugs like Ozempic and Wegovy. Prior to Futurism, I worked for publications ranging from Media Matters and Truthdig to Raw Story and Bustle. I'm also the author of "Myspace Scene Queens," a 2024 title in Instar Books' acclaimed "Remember the Internet" series. My work at Futurism has been cited by outlets including the New Yorker, Slate, Nieman Lab, the Verge, the MIT Technology Review, the Sunday Times, and the Daily Beast. I grew up in North Carolina, attended the University of North Carolina at Asheville, and now live in Brooklyn, New York. In my free time, I'm an avid reader and music fan; you can probably find me at a local poetry reading, concert, underground rave, or DJ set. I'm the proud parent of an ineffable orange cat named Mee-Mow.

### Author social links  
[Bluesky](<https://bsky.app/profile/noorfromfuturism.bsky.social>)