The 23andMe incident exposed a bad property of social DNA features: access to one account can reveal information about other people who never lost their passwords. The company’s later SEC filing said attackers used reused credentials to enter a small share of accounts, then accessed many more DNA Relatives profiles linked to them.
I initially described this as simple scraping and implied strong passwords and two-factor authentication could not help. That blurred the mechanism. Unique passwords and two-factor authentication can protect an individual account; they cannot by themselves stop a relative’s compromised account from exposing shared profile information.
I still think that is an uncomfortable bargain. A feature designed to find family connections also expands the circle of people who can see data about you. I would want clearer controls over what relatives can view and a plain explanation of how one compromised login affects the wider network. Genetic information cannot be reset like a password.
