In 2023, attackers didn’t need stealthy tactics to wreak havoc on 23andMe, they just logged in.

Using passwords stolen from other breached sites, they spent five months going after 23andMe’s login page. Nothing flagged the traffic as suspicious. By the time anyone noticed, 14,000 accounts were gone¹.

The loss might sound contained. It was anything but. 23andMe’s DNA Relatives feature linked customers to biological matches across the platform. Those 14,000 accounts were connected to 6.9 million people’s genetic data. Ancestry, health predispositions, family trees, all exposed. Data customers had expected the company to protect.

Trust evaporated and it didn’t come back. Lawsuits hit hard and fast. So did account deletion requests.

In March 2025, 23andMe filed for bankruptcy. All because of some reused passwords and an authentication system that had no way to tell a legitimate login from an attacker working through a stolen credential list.

23andMe is an extreme case but the underlying problem isn’t. When authentication is too weak, attackers get in. If it’s too aggressive, customers walk out. Both cost you.

This guide walks through how risk-based Multi-factor Authentication (MFA) solves that problem, creating an authentication system that stops real threats without making legitimate customers feel like suspects.