The Blast Radius of a Reused Password

The Blast Radius of a Reused Password

Tech News 23andme data breach dna-testing password-security privacy

So the 23andMe story broke today and it's got a detail in it that I can't stop thinking about, and it's not the part everyone's going to lead with.

Quick recap for anyone who missed it: 23andMe confirmed that user data got scraped and is now up for sale on a hacking forum. The initial batch that showed up for sale was described as data from a million-plus users of Ashkenazi Jewish descent, and there's apparently a second dataset tied to users with Chinese ancestry. Names, birth years, general location, that kind of thing. Not your raw genetic sequence, thankfully, but still deeply personal stuff that most people assumed was locked up somewhere behind a login screen and a privacy policy nobody read.

Here's the part that actually got me. 23andMe is saying this wasn't a break-in to their systems in the traditional sense. It was credential stuffing, meaning someone took a giant pile of usernames and passwords leaked from some other breach (could be from anywhere, LinkedIn, Adobe, some forum from 2016, who knows) and just tried them against 23andMe's login page. And because a chunk of people reuse the same password everywhere, some of those logins worked.

That part alone isnt new. Credential stuffing is basically the laziest form of hacking there is and its been happening for a decade. Whats different here is what happened after someone got into even a small number of accounts. 23andMe has this opt-in feature called DNA Relatives that shows you people in their database who share DNA with you, basically a genetic social network. So if an attacker compromises a few thousand accounts through stuffed credentials, but each of those accounts is opted into DNA Relatives and connected to dozens or hundreds of genetic matches, the actual blast radius balloons out to millions of profiles that were never directly hacked at all. Early numbers floating around suggest something like 14,000 accounts were directly compromised, but the scraped data covers something closer to 6.9 million people. Your cousin's bad password habits just became your problem, and you never even signed up to be exposed.

I do not have a 23andMe account. I spat in a tube for one of these companies exactly once, years ago, mostly out of curiosity about where my grandfather's side of the family actually came from, and I remember sitting there afterward thinking "well this data is out there forever now, nothing to be done about it." Turns out that instinct was correct, just for a slightly different reason than I expected. I figured the risk was the company itself getting breached at the database level, some SQL injection nightmare scenario. Nobody warned me the risk was my third cousin reusing "Password1!" across six sites.

If youve got a genetic testing account anywhere, and honestly this applies to basically every account you have, go turn on two-factor authentication right now. Not "later today." Right now, before you finish reading whatever else is open in your other tabs. 23andMe is pushing people toward it as part of their response, and it should have been the default from day one for a service that holds this category of information. I'll admit I'm guilty of dragging my feet on 2FA for accounts that felt "low stakes" to me, streaming services, random forums, that sort of thing. This is a good reminder that the account itself doesnt have to feel high stakes for the data behind it to be.

The other thing I keep coming back to is how this makes password reuse into a genuinely collective problem instead of a personal one. Usually the pitch for using a password manager and unique passwords everywhere is framed selfishly: protect yourself. Fair enough, that's reason enough on its own. But this breach is a pretty stark example of your bad habits leaking sideways onto people who did everything right. Your sister used the same password on her old MySpace account and your shared genetic data is now sitting in a forum post somewhere. That's a strange kind of externality to wrap your head around.

Anyway. Go check if you've got 2FA on, and if you're one of the people still using the same password from 2014 on more than one site, today's as good a day as any to stop. I say this fully aware I've got at least two accounts I still need to fix myself.