logo
Talk to an Expert
Share:

What 5 Months of Undetected Access Means for Your Organization's Cybersecurity

July 11, 2026 Newsletter

image

What 5 Months of Undetected Access Means for Your Organization's Cybersecurity

California's lawsuit against 23andMe reveals hackers went undetected for 5 months. Learn what credential stuffing attacks mean for your organization — and how to close the gaps before regulators do.

When the Breach Is the Last Thing You Discover
In cybersecurity, the most dangerous attacker isn't the one who breaks down your front door — it's the one who walks in with a stolen key and stays for months.


That's exactly what happened at 23andMe. According to a lawsuit filed by California Attorney General Rob Bonta in May 2026, hackers began accessing the genetics testing firm's systems in late April 2023 and weren't detected until October 2023 — when threat actors started selling stolen data on the dark web. The breach ultimately exposed the personal and genetic data of nearly 7 million users, including over 855,000 Californians.


The attack wasn't sophisticated. It was preventable. And the lessons it holds for mid-to-large enterprises — especially in healthcare, financial services, and manufacturing — are too costly to ignore.

 

What Happened: A Credential Stuffing Attack That Should Have Been Caught


The attack method was credential stuffing — a technique where hackers use usernames and passwords leaked from previous breaches to gain unauthorized access to accounts on other platforms. In this case, investigators allege attackers leveraged credentials exposed in an earlier breach at MyHeritage, a genealogy company that had partnered with 23andMe.


This is not an exotic cyberattack. It is well-documented, well-understood, and well-defended against — when organizations put the right controls in place.
What regulators allege 23andMe failed to do:

Implement mandatory multi-factor authentication (MFA) — Users were not required to verify their identity beyond a simple password
Enforce adequate password requirements — Weak credential standards made accounts vulnerable
Monitor for anomalous login patterns — The company missed clear warning signs of bulk access activity for five months
Prevent bulk data downloading — Once inside, attackers were able to harvest data at scale without triggering alerts

The breach was only discovered when the threat actor posted stolen data for sale online. Not by the company's own security team.

The Regulatory and Financial Fallout Is Severe
Organizations that dismiss breach prevention as a cost center tend to recalculate that position after enforcement actions arrive.
For 23andMe — now operating as Chrome Holding Co. following its March 2025 bankruptcy filing — the consequences have been significant:

$30 million class-action settlement (2024), later increased to up to $50 million, receiving final court approval in January 2026
£2.31 million fine (~$3.1M USD) from the UK Information Commissioner's Office (ICO) and Canada's Office of the Privacy Commissioner, specifically for failing to protect user data and detect the intrusion promptly


Active California AG lawsuit seeking injunctive relief and potentially millions more in fines under state consumer privacy and business practice laws 

Reputational damage severe enough to contribute to the company's bankruptcy

The California DOJ characterized the company's handling of the breach as "entirely unacceptable."

Why This Matters to Your Organization Right Now
If your organization operates in healthcare, financial services, or manufacturing, the 23andMe case is not a cautionary tale about a consumer DNA company. It is a preview of the scrutiny your industry faces.


Healthcare organizations handle patient records, insurance data, and increasingly, genomic information — all heavily regulated under HIPAA and state-level privacy laws. Regulators have demonstrated they will pursue enforcement even after companies file for bankruptcy.


Financial institutions manage credentials, account data, and transaction records that are prime credential stuffing targets. Regulatory bodies including the FDIC, OCC, and state attorneys general are watching how institutions respond to known, preventable attack vectors.


Manufacturers, particularly those with operational technology (OT) environments, often overlook identity and access management on the IT side while focusing on plant-floor security — creating the exact blind spots attackers exploit.


The 23andMe case illustrates a pattern regulators are increasingly using as a template: if a well-known attack vector exists, and you didn't implement well-known defenses, you are liable.

 

The Security Gaps at the Heart of This Breach


1. No Mandatory MFA
Multi-factor authentication is not an advanced control. It is baseline hygiene. Requiring users — and more critically, privileged users and administrators — to authenticate with a second factor would have dramatically limited the blast radius of credential stuffing.
For enterprises, this extends beyond end-user accounts. MFA enforcement must cover service accounts, admin portals, VPN access, and cloud environments including Microsoft Azure Active Directory and other IAM platforms.


2. No Anomaly Detection on Login Behavior
Five months. The attackers had five months of access. This points to a fundamental gap in behavioral monitoring and SIEM (Security Information and Event Management) alerting. Modern threat detection should flag unusual patterns: logins from new geographies, off-hours access, high-volume account queries, and bulk data reads.
If your security team would only find out about an ongoing breach when attackers started advertising their stolen data, your detection posture needs immediate attention.


3. No Data Exfiltration Controls
Even when credentials are compromised, organizations can limit damage through data loss prevention (DLP) controls and access segmentation. The ability to bulk-download sensitive records should require additional authorization — not just a valid login.


4. Credential Hygiene Was Not Enforced
Using previously breached credentials is trivially detectable. Services like Have I Been Pwned and enterprise IAM platforms can flag when users attempt to authenticate with compromised passwords. This is a standard control. It was not in place.

What Organizations Should Do Now
The 23andMe breach is a stress test your organization should run against its own environment — before regulators run it for you.
Immediate priorities:

Enforce MFA across all user and privileged accounts — No exceptions for legacy systems; address them on a prioritized remediation roadmap


Conduct a credential exposure audit — Identify accounts using passwords from known breach databases
Review your threat detection coverage — Can your SOC detect credential stuffing patterns? What is your mean time to detect (MTTD)?


Assess your IAM environment — Particularly if your organization runs Microsoft Active Directory or Azure AD, access hygiene reviews should be conducted annually at minimum


Perform a data access review — Who can download bulk records? Under what conditions? With what logging?

If your organization has not had an independent security assessment recently, the cost of that review is a fraction of what a breach investigation, regulatory fine, and class-action settlement will cost.

InfoSight Can Help You Close These Gaps


At InfoSight, we specialize in helping mid-to-large enterprises identify and remediate exactly the kinds of vulnerabilities that led to the 23andMe breach — before they become a headline.
Our services include:

Microsoft AD & Azure IAM Security Assessments — Identify misconfigurations, overprivileged accounts, and access control gaps in your identity infrastructure


Penetration Testing — Simulate credential stuffing and other real-world attacks to measure your actual exposure


NIST CSF Reviews — Evaluate your security posture against the industry-standard framework, with prioritized remediation roadmaps


OT/IT Security Monitoring — Continuous visibility across both your operational and enterprise environments

The California AG's lawsuit makes one thing clear: "We didn't know" is no longer a defense. The controls existed. The threats were documented. The expectation is that you implement them.


Don't wait for a breach to find your gaps. Contact InfoSight today to schedule a security assessment.

Final Thought: The Breach Nobody Had to Have
The 23andMe breach was not a zero-day exploit. It was not an advanced persistent threat from a nation-state actor. It was credential stuffing — a known technique, using previously stolen credentials, against an organization that had neither the controls to prevent it nor the monitoring to detect it.


Seven million people's genetic data was exposed. A company went bankrupt. And now regulators are using this case to set expectations for every organization that handles sensitive data.


The question for your organization isn't whether a similar attack could happen. It's whether your controls would stop it — and whether your detection would catch it in hours, not months.

Share This Post:

Stay ahead of evolving threats with expert insights

Subscribe to our newsletter to keep you updated on the latest cybersecurity insights & resources.

One follow-up from a security expert—no spam, ever.