My cousin texted me again this week asking if I'd finally done the 23andMe thing. She's been on me about this since her bachelorette party, I think, back when everyone at the table was passing around a phone comparing percentages of Scandinavian ancestry like it was a personality quiz. I still haven't spit in the tube. And this week gave me a pretty good excuse to keep not doing it.
By now you've probably seen the headlines: someone's selling 23andMe user data on a hacking forum. Millions of records, apparently, up for sale in batches. But the part that actually stopped me mid-scroll wasn't the breach itself, it was how they got in. This wasn't some sophisticated zero-day. It was credential stuffing, plain and simple, meaning the attacker just took email/password combos leaked from other, totally unrelated breaches over the years and tried them on 23andMe's login page. A chunk of them worked, because people reuse passwords. That's it. That's the hack.
Here's the part that actually bugs me though. Only a relatively small number of accounts got popped that way directly. But 23andMe has this feature called DNA Relatives, which is opt-in in theory but apparently on by default for a huge share of users, and it lets your profile surface information to people who share DNA with you. So once someone's inside even one compromised account, they can potentially see data belonging to that person's genetic relatives too, people who never reused a password anywhere, never got phished, never did anything wrong except share great-grandparents with someone careless. The listings on the forum were reportedly organized by ancestry, including specifically targeting people with Ashkenazi Jewish heritage. That's not a "check your email for a password reset link" kind of breach. That's a different category of bad, and I don't think the framing of "only X accounts were directly compromised" really captures it.
I'll admit I'm the family holdout on genetic testing for reasons that have nothing to do with security, I just don't love the idea of a private company owning a permanent copy of my genome, full stop. But this is the first time I've had a concrete, specific reason to point to instead of just a vague unease. It's one thing to hand your data to a company and trust their servers. It's another to find out your exposure also depends on whether your second cousin you've never met uses "Password1" everywhere.
And look, I reuse passwords too, or at least I used to before I got dragged kicking and screaming onto a password manager a few years back by a friend who point blank told me I was an idiot for not using one. He was right and I was annoyed about it for a solid month before I admitted it. Most people still haven't made that switch though, and services like this are exactly where that habit turns into someone else's problem, not just your own.
None of this required some elaborate hack. It required exactly one person, somewhere, reusing a password, and a feature designed to connect relatives working exactly as designed. 23andMe's statement basically said user accounts were compromised due to customers using the same password across multiple sites, which, sure, technically true, but also feels a little like blaming the lock when someone hands out a spare key to the whole neighborhood.
If you've got a 23andMe account, or an Ancestry account, or any of these genealogy sites, today's a good day to go check whether you've got two-factor turned on and whether your password there is unique to that one site. It probably isn't. Mine wasn't, for a service I don't even use, which is a sentence that only makes sense if you remember I made an account years ago just to see my mom's side of a family tree someone else had built. I still haven't deleted it. Guess that's this weekend's chore now.