The issue is 23andMe is a honey pot. Thats fundamentally whats at play here.
I only know the meaning where it is a deliberate thing to attract bad actors. Is the entire company not meant to provide genetic information?
They can be unavoidable but need to be well protected. Most companies fail at this.
All it takes is one employee to pip install the wrong library or fall victim to a phishing attack or 3rd party vendor attack and its over. And on a long enough time scale, it happens.
https://en.wikipedia.org/wiki/Honeypot_%28computing%29
TL;DR: A honeypot is like a bait car in a police sting operation; It's something that looks like a vulnerable system with something of value to attackers, but in reality is a fake meant to catch intruders or collect data on them.