23andMe is reportedly turning the blame back on its customers

A major data breach at DNA testing company 23andMe, where attackers used previously leaked passwords from other sites to access about 14,000 accounts and then pivoted via a “DNA relatives” feature to expose data on roughly 7 million users, has raised sharp questions about responsibility and security. Commenters debate how much blame lies with people who reuse passwords versus 23andMe’s failure to enforce stronger protections like mandatory two-factor authentication, rate-limiting, and proactive checks against known compromised credentials. Many also argue that genetic data is uniquely sensitive, affects relatives who never consented, and should be protected under safeguards closer to those used for banking or highly regulated health information.

Breach Mechanics and Scale

  • Attackers used credentials previously compromised on other sites to access ~14,000 23andMe accounts (credential stuffing).
  • From those accounts they used a “DNA Relatives” / “relative finder” feature to view data on roughly 7 million profiles.
  • Commenters note the article is vague: “gain access” likely means viewing relative profiles (names, shared DNA %, locations, genealogical info), not full account takeover for all 7M.
  • Some think media numbers are inflated or misleading, but others argue they reflect how serious large‑scale data linkage is.

Responsibility: Users vs 23andMe

  • One camp says password reusers bear significant blame; 23andMe’s own password store wasn’t breached.
  • Another camp argues providers must assume users reuse passwords and design for that; blaming users is seen as deflection.
  • Several liken 23andMe’s duty of care to banks or at least to platforms holding highly sensitive information, affecting relatives who never signed up.

Proposed and Missing Security Measures

  • Many argue 2FA should have been mandatory from the start, especially for biometric/genetic data; 23andMe only enforced it after the incident.
  • Suggested controls:
    • Credential-stuffing defenses and rate limiting across IPs/accounts.
    • Using Have I Been Pwned–style checks against known leaked passwords.
    • Device/location/IP risk scoring and extra challenges (email links, SMS, app prompts, CAPTCHAs).
  • Some practitioners note that in reality many companies ignore such recommendations, viewing them as costly or bad for conversion.
  • Others push back on mandatory 2FA, citing usability, lack of universal support (e.g., passkeys), and privacy concerns about device/phone tracking.

DNA Relatives Feature and Consent

  • Feature lets opted‑in users see a list of genetic relatives (often thousands of people) and details like name, approximate location, and shared DNA segments.
  • Users thought they were sharing only with a small circle of confirmed relatives; instead, attackers could aggregate millions of profiles via a few thousand compromised accounts.
  • Affected users report being told their own passwords were not misused; their data leaked solely because they appeared as relatives of breached accounts.
  • Some compare this to Facebook: compromising one account reveals friends‑only data for many others; others say that with DNA the stakes are much higher.

Sensitivity and Downstream Risks of Genetic Data

  • Debate over “how critical” this data is:
    • Skeptical view: attackers can’t easily commit identity theft; advertisers don’t need genes when behavior data suffices.
    • Concerned view: genetic data can be linked to marketing profiles, used for disease‑targeted advertising, sold to unregulated third parties, or misused by insurers/employers.
  • Commenters highlight broader impacts:
    • DNA implicates relatives who never opted in; one person’s test can reveal family secrets or medical risks.
    • Law enforcement already uses genealogy databases (e.g., high‑profile serial killer cases, DNA retention from arrestees).
    • Governments and national gene banks collecting DNA raise long‑term civil liberties questions.

Regulation, Comparisons, and Broader Concerns

  • Some argue services like this should be regulated more like financial institutions or critical infrastructure, given the irreversibility of genetic exposure.
  • Others respond that today they are not regulated that way; users knowingly gave wide, long‑term permissions to a lightly regulated startup.
  • Comparison to social networks: for many customers, the core value is exactly this large‑scale sharing/matching, so prohibiting it may require regulatory rather than product‑level fixes.

Critiques of Coverage and Communication

  • Several call the original article low on technical detail and high on finger‑pointing, especially around the “14k → 7M” narrative.
  • 23andMe’s public messaging is widely criticized as tone‑deaf: seen as emphasizing user fault, minimizing its own design and security lapses, and inviting legal and reputational backlash.