Uh, I initially dismissed this as a basic attack on credential stuffing. But...<p><i>> However, in this case, the cybercriminal sells a very large number of 23andMe profiles, which is unlikely to have been compromised directly using the aforementioned method.</i><p><i>> The firm’s spokesperson explained to RestorePrivacy that this is due to an optional feature that interconnects relatives and DNA matches on the platform, which was active on all the compromised accounts. This led to the magnification of the impact from a few breached accounts to the massive numbers we see on the forum post.</i><p>Also, previous discussion: "<i>23andMe says user data stolen in credential stuffing attack</i>" (292 comments) - <a href="https://news.ycombinator.com/item?id=37794379">https://news.ycombinator.com/item?id=37794379</a>