DNA Test Data Breach History: A Timeline Through 2026
Major breaches at consumer DNA companies, dated and sourced. 23andMe 2023, MyHeritage 2018, DNA Diagnostics Center 2021, and what was actually exposed in each.
We treat the breach record of any consumer DNA company as part of the buying decision. A privacy policy describes what a company intends. Its breach history describes what has actually happened. Here is a dated catalog of the largest publicly known incidents at consumer DNA companies and adjacent labs, with what was actually exposed in each.
23andMe, October 2023
23andMe disclosed in October 2023 that an attacker had accessed accounts through credential stuffing, using usernames and passwords leaked from other breaches to log in where users had reused them. The company’s subsequent disclosures and SEC filings put the total scope at roughly 6.9 million users affected, of whom about 14,000 had their account directly compromised. The remaining accounts were swept up through the DNA Relatives matching feature, which exposed match information for relatives of the 14,000 directly-accessed accounts.
The data exposed varied by victim. For directly-accessed accounts it included account information, family-tree data, and in some cases ancestry-composition reports. For users surfaced through DNA Relatives, it included display names, profile information, and predicted relationship data. Specific subsets of data with ethnic ancestry labels were subsequently traded on a hacker forum. A class-action settlement followed in 2024. Our 23andMe data breach settlement explained covers that resolution in detail.
The mechanism is worth underlining. The 23andMe systems were not broken into. Users’ reused passwords, leaked from unrelated services, let an attacker walk in through the front door. Account-level security practices on the user’s side were the failure point.
MyHeritage, June 2018
In June 2018, MyHeritage disclosed that a security researcher had found a file on an external server containing email addresses and hashed passwords for approximately 92 million MyHeritage user accounts. The file was dated October 26, 2017, the date users who signed up before that point would have had their accounts included.
The exposed data was account-level only. Genetic data, family-tree data, and credit-card information were stored on separate systems and were not included in the file. MyHeritage’s blog post of June 4, 2018 was the primary disclosure. The company reset affected passwords and added two-factor authentication options.
DNA Diagnostics Center, 2021
DNA Diagnostics Center is a paternity and forensic-DNA lab, not a genealogy-style consumer testing company, but it sits in the same data class. In late 2021 the company disclosed a ransomware-style intrusion affecting customer records from a national genetic-testing database it acquired in 2012. The disclosed scope was approximately 2.1 million individuals, with the most sensitive subset of approximately 45,000 including Social Security numbers and payment-card data alongside personal information. The lab notified state attorneys general, and the incident appears in the Maine AG breach database.
Smaller and adjacent incidents
The Vitagene exposure was reported by TechCrunch in 2019, when health reports tied to thousands of customers were found on a publicly accessible cloud bucket. The data was customer-reported context attached to genetic analyses, not the raw genotype data itself.
GEDmatch’s reconfigured opt-in settings during a 2020 incident briefly exposed kit records to a broader pool of users than they had consented to; the company described it as a misapplied configuration change rather than an external attack, and reset the affected settings.
What the pattern tells us
Three things stand out across these incidents.
Credential stuffing is the most common attack vector, not network intrusion. Reusing passwords across services is the single largest factor under a user’s own control.
The data most often exposed is account-level information, not raw DNA sequence data. Raw genotype data is usually stored separately and was not included in the largest breaches.
A company that has had no public breach is not a company with no risk. It may simply be a company that has not been targeted yet, or one that has not detected an incident.
Our DNA test account security tips and how to do a DNA test more privately articles cover what to do on your side. For the broader picture, the genetic data privacy pillar is the place to start. If you have an account at a company in this list and want to leave, how to delete your 23andMe data and how to delete your AncestryDNA data walk through the steps.