DNA Test Account Security: 9 Practical Tips for 2026
Concrete account-hardening steps for AncestryDNA, 23andMe, MyHeritage, and FamilyTreeDNA, including 2FA options and lessons from the 2023 23andMe breach.
The 2023 23andMe breach is a useful starting point because it was not a hack of 23andMe’s servers. It was credential stuffing, meaning attackers took username and password pairs that had leaked from unrelated sites and tried them against 23andMe accounts. The pairs that worked unlocked real accounts, and from there the DNA Relatives feature did the rest of the damage by exposing relative data. The lesson is concrete. Reusing a password from somewhere else, even an old account, is the single biggest risk to a DNA test account. The tips below are ordered by impact.
1. Use a unique password, generated by a manager
A password manager, whether a standalone product or the one built into your browser or operating system, lets you keep a long random password unique to each site without remembering any of them. The point is not strength alone, it is uniqueness. A unique 12-character random password is safer than a memorable 20-character one that you also use somewhere else.
2. Turn on two-factor authentication
As of early 2026, two-factor authentication is supported by AncestryDNA, 23andMe, and MyHeritage. FamilyTreeDNA’s support is partial and worth checking on the live account-settings page. Turn it on the day you create the account.
3. Prefer an authenticator app over SMS
SMS-based two-factor authentication is better than nothing, but text messages can be intercepted through SIM-swap attacks. An authenticator app such as Authy, 1Password, Bitwarden, or Google Authenticator generates codes locally on your phone and is not vulnerable to that attack. Where a site offers both, choose the authenticator app.
4. Use a dedicated email address
Creating the account with a dedicated email, separate from your main inbox, has two benefits. It reduces the chance that a breach elsewhere exposes the email used for your DNA account, and it makes phishing easier to spot because legitimate DNA-test mail is the only thing you should ever receive at that address.
5. Watch for phishing
Phishing emails impersonating DNA test companies surge after every publicly disclosed breach. The pattern is usually an alarming subject line about your account being suspended or your results being ready, with a link to a fake login page. The fix is mechanical. Never log in from an email link. Open a new browser tab and type the company URL manually.
6. Review connected apps and integrations
If you have ever uploaded your raw data to a third-party site such as GEDmatch, DNA Painter, Promethease, or any health analysis service, those uploads are separate accounts with separate security postures. A breach of a third-party service exposes the raw data you uploaded there, not just an analysis. Audit periodically and delete what you no longer use.
7. Check what your account is sharing
Each of the major tests has a separate setting for relative matching, research participation, and family-tree linkage. These are not the same toggle and are not always on the same screen. Confirm each one matches your intent, especially after any privacy-policy update.
8. Be careful about recovery methods
The password-reset flow is often the weakest part of an account. Confirm that the recovery email and phone number on file are still yours, are still secure, and are not an old work email you no longer control.
9. Plan for the account outliving you
This is the one most people skip. If you have shared family-tree work or matches that relatives rely on, write down where the credentials live and how to recover them. Without that, your DNA account becomes an unrecoverable asset the moment you cannot log in.
Related reading
For the broader checklist, see our DNA testing privacy checklist. For the 23andMe breach context, see 23andMe data breach settlement explained. The full privacy pillar is at genetic data privacy. For account-deletion steps, see how to delete your 23andMe data.