Eh, millions of accounts hacked via credential stuffing on one platform because of reused passwords? I don't buy it for one second.
Regardless, the key quote from the linked article:
"23andMe blamed the incident on its customers for reusing passwords, and an opt-in feature called DNA Relatives, which allows users to see the data of other opted-in users whose genetic data matches theirs. If a user had this feature turned on, in theory it would allow hackers to scrape data on more than one user by breaking into a single user’s account."
Not all compromised credentials are used in credential stuffing attacks.