up:: What’s At Risk

Is my DNA data safe?

No, and it’s the one category where that answer has no qualifiers on it.

Every other kind of personal data can eventually be changed, replaced, or outlived. A credit card gets reissued. A password gets reset. An address changes. Your genome does none of that. It identifies you for your entire life, it identifies your relatives who never agreed to anything, and there’s no version of the future where it stops being yours.

That makes it the clearest possible case for the whole problem, because it fails every timeline test at once.

The short version:

  • A DNA sample can’t be truly anonymized, and that’s the NIH’s own position rather than an outside opinion.
  • Your test exposes your relatives. Roughly 60% of searches in genealogy databases for a person of European descent in the U.S. already turn up a third cousin or closer.
  • More than 26 million people had put their DNA into the four big commercial databases by the start of 2019.
  • It already went wrong. 14,000 accounts entered with reused passwords exposed 6.9 million people, almost none of whom had their own account touched.
  • Then it went wrong a second way. 23andMe filed for bankruptcy in March 2025, and the genetic data became an asset that could be sold.
  • You can request deletion, and in several states you have a legal right to.

Why is DNA different from everything else?

Because of what it keeps being true about.

A genome identifies its owner for life. It also partially identifies that person’s children, parents, and siblings, which means one person’s decision reaches people who were never asked. The National Human Genome Research Institute states the core problem directly: a DNA sample can never be truly anonymized.

Research published in Science put a number on how far that reach goes. Roughly 60% of genealogy-database searches for a person of European descent in the United States already return a third-cousin-or-closer match, which is close enough to identify someone who never took a test in their life.

So a kit bought as a holiday gift enrolls a whole family by implication.

Source: NHGRI, “Genomic Data Privacy,” genome.gov; Erlich, Shor, Pe’er, and Carmi, “Identity inference of genomic data using long-range familial searches,” Science 362(6415), November 2018, science.org.

Ten dots, 6 of them filled, showing that about 6 in 10 genealogy database searches for a person of European descent in the United States already return a third cousin or closer.

Source: Erlich, Shor, Pe’er and Carmi, Science 362(6415), November 2018.

How many people does this involve?

More than 26 million people had contributed DNA to the four leading commercial ancestry and health databases by the start of 2019: roughly 14 million kits at Ancestry, over 9 million at 23andMe, 2.5 million at MyHeritage, and 2 million at Family Tree DNA. The same analysis projected those databases could hold data on more than 100 million people within 24 months.

Read that against the 60% figure above and the arithmetic gets uncomfortable. The number of people identifiable through these databases is far larger than the number who ever mailed in a sample, because the relatives do the identifying.

Source: MIT Technology Review, “More than 26 million people have taken an at-home ancestry test,” February 11, 2019, technologyreview.com.

What actually happened to 23andMe’s customers?

Two separate things, and neither one needed a quantum computer. Together they’re the clearest illustration available of how genetic data actually escapes.

First, the breach

In October 2023, attackers took passwords stolen from other websites and used them to log into roughly 14,000 23andMe accounts, about 0.1% of the company’s users. Nothing sophisticated happened. People had reused a password.

Through the DNA Relatives feature, those 14,000 accounts exposed the data of about 6.9 million people: around 5.5 million through relative matching, and 1.4 million family-tree profiles.

23andMe told the SEC that the attacker got in through individual accounts, describing it as “a very small percentage (0.1%) of user accounts.” California’s attorney general disputes that account of it, alleging in a lawsuit that a threat actor was inside 23andMe’s systems undetected for 5 months and exploited a coding error in the DNA Relatives feature to reach the rest. A multistate investigation by 42 states found the company had failed to guard against credential stuffing, which is a well-known attack. The resulting settlement is headlined at 18 million.

Both characterizations are on the record, and the difference between them matters, so this page states which is whose rather than picking one.

So 14,000 careless password choices reached 6.9 million people, almost none of whom did anything wrong. That’s the family-exposure mechanism, demonstrated in the real world.

Bar chart contrasting 14,000 accounts the attacker entered against 6.9 million people whose data was taken, an exposure roughly 490 times larger than the intrusion.

Source: California and Texas Attorneys General.

Source: HIPAA Journal reporting on 23andMe’s SEC filing and customer notifications, hipaajournal.com; Office of the Texas Attorney General, “Attorney General Paxton Secures $150 Million Settlement Against 23andMe Over Data Breach That Exposed Genetic Information of 6.9 Million People,” texasattorneygeneral.gov.

Then, the bankruptcy

On March 21, 2025, the California Attorney General issued an urgent consumer alert telling 23andMe customers to consider deleting their genetic data and destroying any stored biological samples, because the company was in financial distress.

Bonta’s framing: “California has robust privacy laws that allow consumers to take control and request that a company delete their genetic data.”

On March 23, 2025, 23andMe filed for Chapter 11 bankruptcy. Genetic data collected from millions of people was among the company’s assets. Attorneys general in several states urged residents to delete their data before it could change hands, and the company was subsequently sold and renamed. California is now suing the entity as Chrome Holding Co., formerly known as 23andMe.

Source: California Office of the Attorney General, “Attorney General Bonta Urgently Issues Consumer Alert for 23andMe Customers,” March 21, 2025, oag.ca.gov; California Office of the Attorney General, “Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach,” oag.ca.gov.

The two events side by side

The breachThe bankruptcy
WhenOctober 2023March 2025
What happened14,000 accounts entered with reused passwordsChapter 11 filing, genetic data among the assets
Who was affected~6.9 million peopleMillions of customers
Was the company hacked?23andMe says no. California alleges a threat actor was inside its systems for 5 monthsNot applicable
Did anyone warn people?Notification letters afterwardState attorneys general, days before
Could a customer prevent it?NoYes, by deleting first

So where does quantum come into it?

Everything above happened without anybody breaking any encryption. A password got reused, and later a company ran out of money.

The quantum version reaches the same place by a quieter route. Genetic data crossing a network today can be copied and stored while it’s still scrambled, then read years later once a machine exists that can undo the scrambling. In that version nobody logs in, nothing changes hands, no bankruptcy gets filed, and no state attorney general issues an alert giving you a chance to delete anything in time.

Your genome will be exactly as identifying then as it is now, which is the whole reason it sits at the top of the risk list.

More on the mechanism at Is someone stealing my data right now?

What can I actually do?

  1. Request deletion if you’ve tested. In California you have a right to under the Genetic Information Privacy Act and the California Consumer Privacy Act, and several other states have comparable laws. Ask for stored physical samples to be destroyed too, which is a separate request.
  2. Think hard before the next kit. This is the one decision that’s still fully yours. It can’t be undone afterward, and it enrolls relatives who don’t get a vote.
  3. Talk to your family before testing. Because a test reveals information about siblings, parents, and children, it’s reasonable to treat it as a shared decision rather than a personal one.
  4. Check what you agreed to. Research consent, third-party sharing, and what happens to your data if the company is sold are usually separate settings.
  5. Ask a testing company directly what its post-quantum plan is, and what happens to your data in an acquisition. There’s a template for that.

Questions people ask

Can I take it back once I’ve tested? You can request deletion of the data and destruction of the sample. Anything already shared, matched, or copied elsewhere is a harder question, and honestly nobody can guarantee you a clean reversal.

What if my sibling tested and I didn’t? Then you’re partially in the database anyway. That’s the part of this with no individual remedy, and it’s the strongest argument for treating testing as a family conversation.

Is medical genetic testing different from an ancestry kit? The privacy laws differ, and the data doesn’t. Clinical genetic testing is generally covered by health-privacy rules that consumer kits often aren’t, which affects who can share it, but the underlying permanence is identical.

Does law enforcement use these databases? Yes, and that’s the use case the Science research above was written about. It’s a separate debate from this one, and it runs on the same property: relatives identify each other.

Should I panic about a test I took in 2018? No. Be clear-eyed that it’s out there, request deletion if you want it gone, and put your attention on decisions you can still make.

Where to go next

Go deeper into the technical detail

The technical catalog is What Data Is Vulnerable to Harvest Now, Decrypt Later.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.