Skip to main content
WhatTermsWhatTerms
← Back to 23andMe

Breach exposure

Public breaches involving 23andMe

Cross-matched against the WhatTerms breach catalog. Each entry links the breach disclosure, names the data classes confirmed exposed, and matches each class to a concrete recovery action — not just “your email was leaked”.

Recovery actions

Sorted by severity. Each action maps to one or more data classes confirmed exposed across the breaches below.

  • Request written attestation that your biometric template was deleted. Biometrics cannot be rotated.

    Critical

    Biometrics are immutable — leakage is permanent.

  • Treat DOB as a leaked secret on knowledge-based authentication. Switch any KBA-protected account to MFA.

    High

    DOB is a top-3 KBA factor and unrecoverable.

  • Add the leaked address to your data-broker opt-out scope (DeleteMe / Optery / Kanary).

    High

    Addresses fuel doxxing and physical-world risk.

  • File a HIPAA breach attestation with HHS (US) and request a written deletion attestation from the service.

    High

    Health data leaks are non-recoverable and disclosure-mandated.

  • Switch this service to a per-service email alias and treat the leaked address as compromised.

    Medium

    Exposed emails feed phishing campaigns and credential-stuffing lists.

  • Audit accounts where you reuse this handle; assume it can be cross-correlated.

    Medium

    Handle reuse links pseudonymous accounts back to your real identity.

23andMe

Disclosed 2023-10-06 · 6.9M accounts

Credential-stuffing chained into the DNA Relatives feature; ancestry and genetic data exposed.

Data classes exposed

  • Email address
  • Username / handle
  • Date of birth
  • Home address
  • Biometric / DNA data
  • Health / medical data

Source: 23andMe disclosure and SEC 8-K filing. Read disclosure ↗