{"id":193166,"date":"2025-06-18T01:37:12","date_gmt":"2025-06-18T01:37:12","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/193166\/"},"modified":"2025-06-18T01:37:12","modified_gmt":"2025-06-18T01:37:12","slug":"uk-fines-23andme-for-profoundly-damaging-breach-exposing-genetics-data","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/193166\/","title":{"rendered":"UK fines 23andMe for \u2018profoundly damaging\u2019 breach exposing genetics data"},"content":{"rendered":"<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"23andMe\" height=\"900\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2025\/06\/23andMe.jpg\" width=\"1600\"\/><\/p>\n<p>The UK Information Commissioner&#8217;s Office (ICO) has fined genetic testing provider 23andMe \u00a32.31 million ($3.12 million) over &#8216;serious security failings&#8217; that led to a &#8216;profoundly damaging&#8217;\u00a0data breach in 2023.<\/p>\n<p>The data protection watchdog said today that 23andMe failed to protect the sensitive data of UK residents who had their genotype data, health reports, and personal information stolen in credential stuffing attacks using stolen login credentials that went unnoticed for five months between April 2023 and September 2023.<\/p>\n<p>&#8220;This was a profoundly damaging breach that exposed sensitive personal information, family histories, and even health conditions of thousands of people in the UK,&#8221; <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2025\/06\/23andme-fined-for-failing-to-protect-uk-users-genetic-data\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> John Edwards, UK&#8217;s Information Commissioner. &#8220;As one of those impacted told us: once this information is out there, it cannot be changed or reissued like a password or credit card number.&#8221;<\/p>\n<p>As the genomics company disclosed in <a href=\"https:\/\/oag.ca.gov\/system\/files\/CA%20AG%20-%20CA%20Notification%20Letters.pdf\" target=\"_blank\" rel=\"nofollow noopener\">data breach notification letters<\/a> sent to impacted individuals, some of this extremely sensitive stolen data was released on the unofficial 23andMe subreddit site and the BreachForums hacking forum.\u00a0<\/p>\n<p>The leaked information included the data of <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hacker-leaks-millions-of-new-23andme-genetic-data-profiles\/\" target=\"_blank\" rel=\"nofollow noopener\">4.1 million people<\/a> living in the United Kingdom and Germany, as well as that of <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack\/\" target=\"_blank\" rel=\"nofollow noopener\">1 million Ashkenazi Jews<\/a>.<\/p>\n<p>After discovering this extensive breach, 23andMe implemented measures to block similar incidents, including <a href=\"https:\/\/blog.23andme.com\/articles\/enhanced-customer-security-at-23andme-with-2-step-verification\" target=\"_blank\" rel=\"nofollow noopener\">enabling two-factor authentication by default<\/a> and requiring customers to <a href=\"http:\/\/blog.23andme.com\/articles\/addressing-data-security-concerns\" target=\"_blank\" rel=\"nofollow noopener\">reset passwords<\/a>.<\/p>\n<p>&#8220;As part of our regulatory process, we took into consideration representations from 23andMe, before deciding on whether to impose a financial penalty, and the final amount of the penalty,&#8221; an ICO spokesperson told BleepingComputer when asked how the fine amount was calculated.\u00a0<\/p>\n<p>&#8220;The amount of this fine has been set in accordance with our\u00a0<a href=\"https:\/\/ico.org.uk\/about-the-ico\/our-information\/policies-and-procedures\/data-protection-fining-guidance\/\" target=\"_blank\" title=\"https:\/\/ico.org.uk\/about-the-ico\/our-information\/policies-and-procedures\/data-protection-fining-guidance\/\" rel=\"nofollow noopener\">Data Protection Fining Guidance | ICO<\/a>. This\u00a0<a href=\"https:\/\/ico.org.uk\/about-the-ico\/our-information\/policies-and-procedures\/data-protection-fining-guidance\/statutory-background\/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018\/\" target=\"_blank\" rel=\"nofollow noopener\">specific section<\/a> of the fining guidance details the maximum amount we may fine a company.&#8221;<\/p>\n<p>This fine comes after the California-based genetic testing provider <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/23andme-files-for-bankruptcy-customers-advised-to-delete-dna-data\/\" target=\"_blank\" rel=\"nofollow noopener\">filed for Chapter 11 bankruptcy<\/a> in late March and announced that it plans to sell its assets following multiple years of financial struggles.<\/p>\n<p>The 2023 data breach has <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/23andme-hit-with-lawsuits-after-hacker-leaks-stolen-genetics-data\/\" target=\"_blank\" rel=\"nofollow noopener\">led to multiple class-action lawsuits<\/a>, which prompted 23andMe to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/23andme-updates-user-agreement-to-prevent-data-breach-lawsuits\/\" target=\"_blank\" rel=\"nofollow noopener\">amend its Terms of Use in November 2023<\/a> to make it harder to get sued. However, the company claimed the changes only aimed to simplify the arbitration process.<\/p>\n<p>In September 2024, the DNA testing giant <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/23andme-to-pay-30-million-in-genetics-data-breach-settlement\/\" target=\"_blank\" rel=\"nofollow noopener\">agreed to pay $30 million<\/a> to settle a lawsuit over the 2023 data breach that had exposed the data of 6.4 million customers worldwide.<\/p>\n<p>        <a href=\"https:\/\/www.tines.com\/access\/guide\/unlocking-it-agility-with-automation-patch-management\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=june-in-article-banner\" target=\"_blank\" rel=\"noopener sponsored\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/uk\/wp-content\/uploads\/2025\/06\/tines-needle.jpg\" alt=\"Tines Needle\"\/><br \/>\n        <\/a><\/p>\n<p>Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.<\/p>\n<p>In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work &#8212; no complex scripts required.<\/p>\n<p>        <a href=\"https:\/\/www.tines.com\/access\/guide\/unlocking-it-agility-with-automation-patch-management\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=june-in-article-banner\" target=\"_blank\" rel=\"noopener sponsored\">Get the free guide<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"The UK Information Commissioner&#8217;s Office (ICO) has fined genetic testing provider 23andMe \u00a32.31 million ($3.12 million) over &#8216;serious&hellip;\n","protected":false},"author":2,"featured_media":182804,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3846],"tags":[267,70,16,15],"class_list":{"0":"post-193166","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-genetics","8":"tag-genetics","9":"tag-science","10":"tag-uk","11":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114701811343408355","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/193166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=193166"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/193166\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/182804"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=193166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=193166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=193166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}