osec.one case analysis cover: credential stuffing and data amplification

Credential stuffing is the least glamorous attack on the internet: take username and password pairs leaked from one site and try them on another. It works because people reuse passwords. At 23andMe in 2023 it worked on only about 0.1% of accounts, roughly 14,000, yet the company ended up confirming that data about 6.9 million people had been taken.

The gap between those two numbers is the lesson. The attacker didn't need many accounts, because each one could see data about thousands of other customers. In June 2025 the UK Information Commissioner's Office (ICO) fined 23andMe £2.31 million, after a joint investigation with the Privacy Commissioner of Canada, for failing to protect the data of 155,592 UK residents.

Attack chain: leaked passwords from other breaches, automated login attempts, about 14,000 accounts opened, DNA Relatives profiles scraped, data advertised on forums, discovered via Reddit post
Credential stuffing plus a sharing feature: a few thousand logins exposed millions of profiles.

Step 1: a list of other people's passwords

23andMe said the usernames and passwords used to get in "were the same as those used on other websites" that had been compromised. Combo lists of this kind circulate freely, built from years of breaches and infostealer logs. Like most consumer services, 23andMe used email addresses to sign in, so matching a leaked email and password to a 23andMe account took no guesswork. The ICO later listed predictable usernames among the failings.

Step 2: automated logins over months

According to the ICO, the campaign ran from April to September 2023, with the most intense credential stuffing in May and another wave in September. Automated tools try each pair against the login endpoint, usually through large pools of proxy IP addresses so that no single address sends enough attempts to trip a simple rate limit. Most attempts fail. The ones that succeed are kept.

Two things made success likely. Multi-factor authentication was optional, so a correct password was enough. And there was no check on whether a password had already appeared in a known breach.

Step 3: one account, thousands of relatives

Many customers had opted in to DNA Relatives, which shows each user the names, birth years, locations, ancestry and shared DNA percentages of their genetic matches. From the roughly 14,000 accounts it opened, the attacker collected profile information on about 5.5 million DNA Relatives users and 1.4 million Family Tree profiles. The feature worked as designed. The ICO found 23andMe lacked effective systems to monitor and detect threats to customer data, so nothing stopped a handful of accounts pulling far more data than a person ever would.

Credential stuffing decides how many accounts fall. Your data model decides how much each one exposes.

Step 4: sale, and discovery

In early October 2023 records appeared on cybercrime forums, first about a million, then millions more. The ICO found that 23andMe had looked into unauthorised access in isolated investigations in July 2023, and in August dismissed a claim of stolen data on more than 10 million users as a hoax. A full investigation started only in October, after an employee saw the stolen data advertised in a post on Reddit.

What 23andMe changed

• Required all customers to reset their passwords (October 2023).
• Temporarily disabled some DNA Relatives features.
• From 6 November 2023 made two-step verification mandatory for all customers, with email codes by default and authenticator apps as an option.
• The ICO said its security improvements were sufficient to stop the kind of attack seen only by the end of 2024.

Controls that break each step

Make the stolen password useless

• Check passwords against breach corpuses at sign-up, login and reset, and refuse known-breached ones.
• Require a second factor, at least for new devices and for access to sensitive data. Better, drop passwords: a one-time code to the user's email or phone, or Apple/Google sign-in, leaves no password for anyone to reuse.

Make automation expensive

• Rate limit by account and by IP, and watch the global failure rate. A credential stuffing campaign shows up as a rise in failed logins spread across many accounts and addresses.
• Bot detection and challenges on the login endpoint.
• Alert on successful logins from new devices or hosting and proxy networks, and notify the account owner.

Limit the blast radius

• Rate limit and monitor data-heavy features such as search, match lists and exports per account.
• Require re-authentication before sensitive downloads (the ICO specifically criticised the lack of extra verification for raw genetic data).
• Default sharing features to the minimum, and make it clear to users what others can see.

Treat claims seriously

A credible claim of stolen data should start an investigation, not a statement that it's a hoax. Watch criminal forums and public sites for your brand, and compare samples against your own records.

The lesson

Nothing in this attack was technically new. Optional MFA, reusable passwords and an unmonitored data feature combined to turn 14,000 compromised accounts into millions of exposed people, and genetic data, as the ICO's John Edwards put it, "cannot be changed or reissued like a password or credit card number".

osec.one gives your app or website one-time-code and Apple/Google logins, with per-IP rate limits, so there is no password to stuff. Free to start.

Add passwordless login

Sources: ICO: 23andMe fined £2.31 million (June 2025); 23andMe: Addressing data security concerns (Oct to Dec 2023 updates); 23andMe: Enhanced customer security with 2-step verification (Nov 2023); TechCrunch: 23andMe confirms hackers stole ancestry data on 6.9 million users; OWASP: Credential stuffing prevention cheat sheet.