What Is Credential Stuffing? The 23andMe Breach Explained

Written by

in

,

By J. Mesa

In early October, 23andMe told customers that someone had accessed user accounts and compiled profile information from its DNA Relatives feature. The company said its own systems were not broken into. The attackers signed in through the front door, with usernames and passwords that customers had also used on other websites. That technique has a name, and it works against any business with a login page.

What happened at 23andMe?

On October 6, 2023, 23andMe published a notice describing the incident. According to the company, attackers used recycled login credentials to get into individual accounts. From inside those accounts, they collected information that other users had chosen to share through DNA Relatives, an optional feature that connects genetic matches. A seller on a hacking forum then advertised lists of profile data.

The reach extended beyond the accounts with reused passwords. Each compromised account could see the shared profile details of its DNA matches, so one weak password exposed information about many people who had done nothing wrong.

23andMe responded by resetting passwords and, starting November 6, requiring two-step verification for all customers. The investigation continues as of this writing.

What is credential stuffing?

Credential stuffing is an attack in which criminals take usernames and passwords stolen from one website and try them, by the million, on other websites. It works because people reuse passwords.

The attacker does not guess. The attacker already holds your real password from an old breach, and bets that you used it somewhere else.

How does credential stuffing work?

  1. Collect. Criminals gather username and password pairs from past breaches. Billions of them circulate on criminal forums, many for free.
  2. Automate. Software feeds those pairs into the login page of a target site. The tools route attempts through thousands of IP addresses to look like ordinary customers.
  3. Sort. The software records each pair that works.
  4. Cash out. The attacker drains stored value, steals personal data, places orders, or sells the working logins to someone else.

The success rate per attempt is low, often well under one percent. At a million attempts, that still yields thousands of open accounts.

Why does credential stuffing work so well?

Because of one habit. Surveys keep finding that a majority of people reuse passwords across accounts. A password you created for a forum in 2014 may still guard your email today. When the forum was breached, that password stopped being a secret. See our post on the most compromised passwords.

How is it different from a brute force attack?

A brute force attack guesses many passwords against one account. Password spraying tries a few common passwords, such as “Winter2023,” against many accounts. Credential stuffing uses known, real pairs. It is quieter and more efficient than either, because each account sees one or two attempts.

How do I know whether my password was in a breach?

  • Search your email address at haveibeenpwned.com, a free service run by a respected security researcher. It lists the known breaches that included your address.
  • Use the password checkup built into your password manager or your browser. Chrome, Edge, Safari, and Firefox all flag saved passwords found in breach data.
  • Watch for signs: password reset emails you did not request, login alerts from unfamiliar places, and orders or messages you did not send.

How do I protect my own accounts?

  1. Use a different password for every account. This single step defeats credential stuffing. A password stolen from one site then opens nothing else.
  2. Use a password manager to create and remember them. Nobody can memorize a hundred unique passwords.
  3. Turn on multi-factor authentication wherever a site offers it, starting with email, banking, and any account that holds sensitive data. An attacker with the right password still lacks the second step.
  4. Change reused passwords now, beginning with your email account. Email is the key to every other account, because password resets go there.
  5. Close accounts you no longer use. Each one is a copy of your data waiting for a breach.

What does this mean for sensitive accounts?

Think about what an account holds, not how often you use it. A genetic testing account contains information you can never change. The same goes for health portals, tax software, and financial accounts. Protect those with your strongest settings even if you sign in once a year, and review what you have chosen to share with other users.

How do I protect my business from credential stuffing?

Your staff reuse passwords too, and their work email address appears in breach lists.

  • Require multi-factor authentication on email, remote access, payroll, banking, and every cloud application that supports it.
  • Provide a business password manager and require unique passwords for work accounts.
  • Block known-breached passwords. Microsoft 365 and other identity systems can refuse passwords that appear in breach lists.
  • Turn on sign-in risk alerts. Have someone review alerts for logins from unfamiliar countries and for impossible travel.
  • Set lockout and throttling rules to slow automated attempts.
  • Turn off old sign-in methods. Legacy email protocols such as POP and IMAP with basic authentication bypass multi-factor authentication. Disable them.
  • Disable accounts when people leave.
  • Train your staff on why a work password must never match a personal one. Our cybersecurity training covers this.

What if my business has customer logins?

If customers sign in to your website, store, or portal, you carry the 23andMe problem in miniature.

  • Offer multi-factor authentication to customers, and require it for accounts that hold sensitive data.
  • Add rate limiting and bot detection to the login page.
  • Check new and changed passwords against lists of breached passwords.
  • Email customers when a login occurs from a new device.
  • Limit what one account can see about other users.
  • Monitor for spikes in failed logins.

When customers lose data through your login page, they hold your business responsible, whoever chose the weak password.

Is the company at fault, or the customer?

Both carry part of it. A customer who reuses a password leaves the door unlocked. A company that holds sensitive data and makes two-step verification optional has decided to accept that risk on its customers’ behalf. Regulators and courts increasingly expect a business to anticipate reused passwords and defend against them. Plan as if your users will reuse passwords, because many will.

What should I do if I have a 23andMe account?

  • Change the password to one you use nowhere else.
  • Turn on two-step verification.
  • Review your DNA Relatives and profile sharing settings, and reduce what you display.
  • Change the password on any other account that shared the old one.
  • Be alert for phishing emails that mention your ancestry or relatives. Attackers use stolen details to make messages convincing.

Your next step

Search your work and personal email addresses at haveibeenpwned.com today. Then change every password you have reused, starting with email. For help setting password and access policies across your business, see our services or contact Cerberus Cybersecurity.