CNN —A hacker or hackers have accessed nearly seven million profiles of 23andMe customers, a spokesperson for the genetic testing firm told CNN on Tuesday, including in some cases users’ ancestry reports, zip codes and birth years.
In addition, the hackers accessed a subset of family tree information on 1.4 million DNA Relatives profiles, the 23andMe spokesperson said in an emailed statement.
In the case of 23andMe, the hackers reused old usernames and passwords from other websites to break into 23andMe customer accounts — a rudimentary but effective technique called credential stuffing.
The 23andMe spokesperson, who declined to be named, did not respond to questions about who carried out the hack.
“We have taken steps to further protect customer data, including requiring all existing customers to reset their password and requiring two-step verification for all new and existing customers.”
Persons:
Okta, 23andMe, ”, “
Organizations:
CNN, Securities and Exchange Commission, Engadget
Locations:
23andMe