UK watchdog fines 23andMe for ‘profoundly damaging’ data breach

UK Fines 23andMe £2.31m for Failing to Prevent Major Data Breach
Photo: BBC

UK Fines 23andMe £2.31m for Failing to Prevent Major Data Breach

The UK’s Information Commissioner’s Office (ICO) has fined DNA testing company 23andMe £2.31 million for a serious data breach that occurred in 2023. The breach stemmed from a credential stuffing attack, where hackers used leaked passwords from other services to gain unauthorized access to 23andMe accounts. Though only 14,000 accounts were directly accessed, data from around 6.9 million people—mostly linked through family connections—was exposed. This included sensitive personal information such as ethnicity, health reports, and family histories, but not DNA sequences themselves.

The ICO determined that 23andMe lacked adequate security protocols, including strong password policies and mandatory multi-factor authentication. The company’s failure to respond quickly to known vulnerabilities left users’ data exposed. Over 155,000 UK residents were affected by the breach. Due to the nature of genetic and health data, such information is considered ‘special category data’ and warrants extra protection under UK law.

While 23andMe has since addressed these vulnerabilities, it filed for bankruptcy and is now set to be acquired by TTAM Research Institute, a non-profit biotech firm led by co-founder Anne Wojcicki. TTAM has pledged to improve data protections and honor user privacy choices, including the ability to delete accounts and opt out of research participation.

Leave a Reply

Your email address will not be published. Required fields are marked *