Site navigation

ICO Partners With Canada to Investigate 23andMe Data Breach

Elizabeth Greenberg

,

ICO 23andMe
The investigation will examine if 23andMe had adequate protections for the sensitive data it processes. 

Following a major breach of 23andMe, the DNA testing and hereditary platform, the UK Information Commissioner’s Office (ICO) is partnering with its Canadian counterpart to investigate the company.

In October 2023, 23andMe, the genetic testing site which harbours deeply personal information such as ethnic backgrounds, medical information, and heraldry linkage, suffered a data breach that affected 6.9 million users.

The company disclosed that it was not aware of the data breach until hackers already had five months of access, and published stolen data on a 23andMe-related subreddit.

The breach affected around half of the company’s userbase, and included information such as names, birthdate, relatives and genetic relation percentages, ancestry reports, and even user locations that had been self-reported.

To access the information of 6.9m users, the hackers only needed the already breached credentials of 14,000 individuals, which could then be used to access information of other users due to a feature called DNA Relatives. Users could opt-in to automatically be linked to genetic relations who also opted-in to the programme in an effort to find long-lost relatives.

The feature made the hacker’s efforts all the more damaging, opening up the door to millions of accounts’ personal information and genetic history.

As a custodian of highly sensitive personal information, 23andMe may face intense scrutiny from the UK and Canadian data protection watchdogs.

Following the data breach and outcry from affected users, 23andMe turned to blaming victims for reusing passwords rather than admitting fault for the data breach, or for users that were affected as a result of their DNA relatives feature.

“People need to trust that any organisation handling their most sensitive personal information has the appropriate security and safeguards in place,” John Edwards, the UK Information Commissioner said in a statement.

“This data breach had an international impact, and we look forward to collaborating with our Canadian counterparts to ensure the personal information of people in the UK is protected.”

The investigation will leverage support from both nations, examining the scope of information exposed and its potential harms, whether 23andMe has adequate safeguards to protect the highly sensitive data, and if the company provided adequate notification about the breach to regulators and affected customers.


Recommended reading


“In the wrong hands, an individual’s genetic information could be misused for surveillance or discrimination,” Phillipe Dufrense, privacy commissioner of Canada, said.

“Ensuring that personal information is adequately protected against attacks by malicious actors is an important focus for privacy authorities in Canada and around the world.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data