NortonShield Pro All articles
Threat Intelligence & Business Security

Spit, Submit, Exposed: The Genetic Privacy Crisis Hiding Inside Consumer DNA Kits

NortonShield Pro
Spit, Submit, Exposed: The Genetic Privacy Crisis Hiding Inside Consumer DNA Kits

Photo: Spudgun67, CC BY-SA 4.0, via Wikimedia Commons

There is no password reset for your genome. Once your genetic data is compromised, it cannot be changed, rotated, or revoked the way a stolen credit card number can. This immutable quality is precisely what makes consumer DNA testing platforms among the most consequential — and underestimated — targets in the modern threat landscape.

Over the past decade, services such as 23andMe, AncestryDNA, and a growing roster of competitors have collected genetic samples from an estimated 40 million Americans. The pitch is compelling: a modest fee, a saliva sample, and weeks later, a detailed portrait of your ethnic heritage, potential health predispositions, and long-lost relatives. What the marketing materials rarely emphasize is that your biological blueprint now resides on a commercial server, governed by terms of service that most users never read, and increasingly targeted by cybercriminals who understand its extraordinary value.

Why Genetic Data Is the Ultimate Identity Asset

Traditional identity theft relies on assembling fragments: a Social Security number here, a date of birth there, perhaps a compromised email address from a decade-old breach. Criminals piece these elements together to impersonate victims, open fraudulent accounts, or access financial institutions.

Genetic data changes the calculus entirely. Your DNA profile does not simply confirm who you are — it reveals who your relatives are, what medical conditions you may develop, and in some cases, details about your ancestry that can be cross-referenced with voter registration records, insurance databases, and public genealogy trees. Researchers have demonstrated that even partially anonymized genetic datasets can be re-identified with remarkable accuracy when combined with other commercially available data sources.

For a sophisticated identity thief, a comprehensive genetic profile is not merely another data point. It is a master key capable of unlocking fraud schemes of unusual depth and durability.

The 23andMe Breach: A Warning the Industry Cannot Ignore

In late 2023, 23andMe disclosed that threat actors had accessed the personal data of approximately 6.9 million users — a figure that ultimately represented nearly half of the company's entire customer base. The attack leveraged credential stuffing, a technique in which criminals test large volumes of previously stolen username and password combinations against a target platform, exploiting the widespread habit of password reuse.

What made this breach particularly alarming was the cascading effect of the platform's DNA Relatives feature, which allows users to share genetic information with matched family members. By compromising a relatively contained set of individual accounts, attackers were able to harvest data from millions of connected profiles who had never themselves been directly targeted. The breach exposed names, birth years, relationship labels, ancestry percentages, and in some cases, self-reported health information.

The incident illustrated a structural vulnerability inherent to genetic platforms: the interconnected nature of their databases means that a single compromised account can radiate outward, exposing individuals who took every reasonable precaution with their own credentials.

From Genealogy to Fraud: How Criminals Monetize Genetic Profiles

The immediate question for most consumers is a practical one: what does a criminal actually do with genetic data? The answer is more varied — and more troubling — than many expect.

Targeted phishing and social engineering. Armed with knowledge of a victim's relatives, health predispositions, and ethnic background, criminals can craft highly personalized deception campaigns. A fraudulent message referencing a specific cousin's name, or alluding to a shared health concern, carries significantly more credibility than a generic scam.

Insurance and healthcare fraud. Genetic health data can be used to fraudulently obtain prescription medications, file false insurance claims, or manipulate medical records. In a healthcare system where identity verification remains inconsistent, this represents a meaningful and underappreciated risk vector.

Long-term identity construction. Sophisticated threat actors do not always act immediately. Stolen genetic data may be archived, combined with information from subsequent breaches, and deployed months or years later as part of a more elaborate identity fraud operation.

Family-based extortion. In documented cases internationally, criminals have used genealogical data to identify and contact relatives of targeted individuals, leveraging family connections to apply pressure or extract payments.

The Consent Problem: What You Actually Agreed To

Beyond criminal actors, the terms governing how DNA testing companies use and share your data deserve scrutiny in their own right. Many platforms reserve the right to share de-identified genetic information with pharmaceutical partners and academic researchers — a practice that generates significant revenue and that users frequently consent to without realizing it.

While the intentions behind such partnerships may be legitimate, the aggregation of de-identified data at scale creates pools of information that security researchers have repeatedly shown can be re-identified. The line between "anonymous research data" and "a detailed profile of you specifically" is thinner than most consumers appreciate.

Furthermore, if a DNA testing company is acquired, merges with another entity, or enters bankruptcy proceedings, the genetic database it holds becomes a corporate asset subject to transfer — potentially to an organization with different privacy standards or security postures.

Protecting Your Genetic Privacy Without Abandoning Curiosity

None of this is an argument against using DNA testing services. For many Americans, these platforms have delivered genuine value — reconnecting adoptees with biological families, identifying hereditary health risks, and illuminating ancestral histories. The goal is informed participation, not avoidance.

Several concrete steps can meaningfully reduce your exposure:

Use a unique, strong password and enable two-factor authentication. The 23andMe breach succeeded largely through credential stuffing — a method that becomes ineffective when passwords are not reused across platforms. A dedicated password manager, paired with robust multi-factor authentication, closes this particular avenue of attack. Norton's own suite of protective tools includes password management features designed precisely for this purpose.

Review and restrict data sharing settings. Most platforms offer granular controls over whether your data participates in research programs, how broadly it is shared with DNA Relatives matches, and whether your profile appears in public family trees. Audit these settings periodically, as platform updates sometimes reset user preferences.

Download your raw data, then consider deleting it from the platform. Many services allow you to export your genetic information before requesting account deletion. If you have extracted the insights you sought, retaining an account — and its associated data — on a commercial server indefinitely introduces ongoing risk with diminishing benefit.

Understand your state's legal protections. Genetic privacy legislation varies considerably across the United States. States including California, Texas, and Florida have enacted specific protections governing how genetic data may be collected and shared. Familiarizing yourself with applicable law in your jurisdiction is a meaningful first step toward asserting your rights.

Monitor for breach notifications proactively. Reactive awareness is insufficient. Services that continuously scan for your personal information appearing in known breach databases — a capability central to Norton's identity monitoring offerings — provide early warning that allows for timely defensive action.

The Immutability Problem and What It Demands of Us

The cybersecurity industry has developed sophisticated responses to most categories of data theft. Compromised passwords can be changed. Stolen credit card numbers can be canceled. Even Social Security numbers, while cumbersome to replace, exist within a system that has procedures for addressing fraud.

Genetic data exists outside that framework entirely. There is no mechanism for issuing a replacement genome. This immutability places an unusually high premium on prevention — on ensuring that your biological information never falls into the wrong hands in the first place, rather than managing the consequences after it does.

The consumer DNA testing industry has delivered remarkable scientific and personal value to millions of Americans. It has also created a category of risk that the broader public has been slow to fully reckon with. Understanding that risk — clearly, without alarm but without complacency — is the necessary foundation for navigating it wisely.

All Articles

Related Articles

Frozen in Time: How Aging Enterprise Software Quietly Became Your Organization's Greatest Security Threat

Frozen in Time: How Aging Enterprise Software Quietly Became Your Organization's Greatest Security Threat

Digital Gold, Real Danger: How a New Breed of Cybercriminal Is Draining Crypto Wallets Across America

Digital Gold, Real Danger: How a New Breed of Cybercriminal Is Draining Crypto Wallets Across America

Silent Billing: How Fraudsters Weaponize Auto-Renewal Features to Quietly Empty Your Accounts

Silent Billing: How Fraudsters Weaponize Auto-Renewal Features to Quietly Empty Your Accounts