23andMe discovered that specific customer profile data that customers had agreed to share through their DNA Relatives function had been gathered from individual accounts without the users' consent.
They launched an investigation as soon as they became aware of any suspicious conduct.
While they are still looking into this situation, they think that when individuals reused login information, threat actors may have gained access to some accounts.
According to the company, the threat actor may then have accessed certain 23andMe.com accounts without authorization in violation of their Terms of Service and obtained information from those accounts, including details about users' DNA Relatives profiles, to the extent a user opted into that service.
Source: https://blog.23andme.com/articles/addressing-data-security-concerns
"id": "23A24161023",
"linkid": "23andme",
"type": "Data Leak",
"date": "10/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"