23andMe tells victims it's their fault that their data was breached
A recent data breach at DNA-testing company 23andMe, attributed to credential stuffing using passwords reused from other hacked services, has exposed information on 6.9 million people and sparked anger over the firm’s claim that users are largely to blame. Commenters argue that a company holding uniquely sensitive genetic and familial data has a duty to enforce stronger protections—such as mandatory multi-factor authentication, better anomaly detection, and checks against known-compromised passwords—rather than relying on user “cyber hygiene.” The incident is also prompting broader criticism of consumer genetic services, including their data-retention practices, permissive default sharing settings, and the lack of strong regulation comparable to health-sector privacy laws.
Nature of the breach & 23andMe’s stance
- Attack described as credential stuffing: passwords leaked from other sites were reused on 23andMe.
- 14k accounts were directly accessed; DNA Relatives features then exposed data on ~6.9M others.
- 23andMe’s legal response largely blames users’ password reuse and claims “reasonable security.”
- Many commenters see this as deflection; others argue that if correct credentials are used, it’s hard to call that a “hack” of 23andMe itself.
User vs. service responsibility
- One camp: services holding extremely sensitive data must assume poor user behavior and build strong defenses; blaming users is unacceptable.
- Another camp: users who reuse passwords or share sensitive data widely must accept consequences; 23andMe is at most partly responsible.
- Several note that affected “relatives” may have used strong unique passwords and still got exposed via others’ bad security.
Missing / inadequate security controls
- Heavy criticism that MFA/2FA was only optional pre‑breach and made mandatory only afterward, seen as tacit admission of prior weakness.
- Suggested mitigations:
- Mandatory MFA or at least MFA for high‑risk actions and “relatives” access.
- Passkeys or hardware tokens.
- Checking passwords against leak databases (e.g., Have I Been Pwned) at signup/login.
- Rate‑limiting, botnet/traffic anomaly detection, IP/location challenges, email verification on new devices.
- Some security practitioners caution that sophisticated, slow botnets can evade many signals; not all credential stuffing is easy to detect.
DNA Relatives feature & blast radius
- Core criticism: platform design allowed compromise of a small number of accounts to reveal data on millions, including cautious users.
- Sharing is technically opt‑in, but UX is described as nudging toward broad sharing with permissive defaults and little risk explanation.
- Debate over whether sharing with distant, effectively unknown cousins is “responsible” behavior.
Sensitivity of genetic data & ethics
- Strong concern that DNA implicates family members who never consented.
- Some argue services like this should meet or exceed banking‑level security; others question whether such services should exist at all.
- Comparisons drawn to Cambridge Analytica’s use of friend‑of‑friend data.
Regulation, law, and deletion
- Discussion that HIPAA generally doesn’t cover consumer DNA companies; FTC might intervene but usually only fines.
- Mention of dozens of lawsuits already filed over the breach.
- Even after “account deletion,” some genetic and identifying data must or does remain, which several see as a deal‑breaker.