What the 23andMe breach really taught us about DNA privacy
In 2023, attackers reached the profile data of nearly seven million people. In 2025, the company filed for bankruptcy and its genetic database became an asset that could be sold. The lesson is not “pick a safer company.”
The breach didn’t require breaking encryption or a sophisticated exploit. It used credential stuffing, reused passwords, amplified by the “DNA Relatives” feature, so reaching one account exposed many. The takeaway is uncomfortable: once your genome sits on somebody’s server, its safety depends on things entirely outside your control.
Then came the bankruptcy. State attorneys general warned customers that the genetic database itself had become a saleable asset. Data you handed over for one purpose can outlive the company you gave it to, and end up somewhere you never agreed to.
The gaps most people don’t know about
GINA, the U.S. genetic-nondiscrimination law, restricts health insurers and employers, but it does not cover life, disability, or long-term-care insurance. And HIPAA does not apply to consumer DNA services at all. The protections most people assume they have, they don’t.
Verinome’s answer isn’t a better promise. It’s a different architecture: your DNA is parsed on your own device and never reaches us. There is no database to breach, no asset to sell, nothing to subpoena. You can’t lose what you never handed over.
Read how local-only analysis actually works, or watch the live counter for yourself.
← All posts