23andMe Hit with £2.3M Fine After Massive Data Breach Exposed Genetic Information of 150,000 UK Residents

The UK Information Commissioner's Office (ICO) fined 23andMe £2.31 million after a 2023 data breach exposed the genetic and personal data of over 150,000 UK residents and millions globally. The breach, which lasted from April to September 2023, involved hackers using credential stuffing attacks to access and scrape health, family, ethnicity, and genetic data, with some of the information later posted online. Investigations by both the ICO and Canada’s privacy commissioner found that 23andMe lacked adequate authentication, including multi-factor authentication, and failed to respond promptly, only acting after data surfaced for sale on Reddit. The breach led to significant fallout, including the company's US bankruptcy filing and impending sale to new ownership committed to improving data protection. Regulators highlighted that genetic data is protected under special UK legal categories and stressed the irreversible harm from such leaks. Privacy advocates noted that, unlike passwords or credit cards, genetic data cannot be changed if compromised.
The breach affected a total of 7 million people globally, including 4.1 million people in the UK and Germany and 1 million Ashkenazi Jews, indicating the wide scale of data exposure beyond just the UK residents.
The breach was discovered only after an employee of 23andMe saw the stolen data being advertised for sale on Reddit, highlighting a delayed detection and response by the company.
23andMe implemented measures after the breach, including enabling two-factor authentication by default and requiring customers to reset passwords to block similar incidents in future.
The hacker exploited a common weakness caused by users reusing passwords that had already been stolen in unrelated data breaches, which allowed credential stuffing attacks to succeed.
The new ownership group, TTAM Research Institute, which is acquiring 23andMe, has made binding commitments to improve protections for customer data and privacy.
Publishers
14
Articles
46
Reach
60