UK Fines 23andMe $3.1M Over Major Genetic Data B…

Please follow & like us :)

URL has been copied successfully!
URL has been copied successfully!
URL has been copied successfully!

If you’re tired of censorship and dystopian threats against civil liberties, subscribe to Reclaim The Net.

A landmark £2.31 million ($3.1 million) fine has been issued against 23andMe by the UK’s Information Commissioner’s Office (ICO), responding to a security failure that compromised the genetic and personal profiles of more than 155,000 UK users.

This penalty follows a separate settlement of $30 million reached in the United States after a broader data breach impacted millions more.

The breach stemmed from a credential stuffing attack in 2023, where cyber intruders used login details previously leaked in unrelated data breaches to infiltrate 23andMe’s systems.

Once inside, attackers accessed a wide array of intimate data, ranging from names and locations to racial background, health reports, and genealogical connections.

This method of attack has become increasingly widespread, exacerbated by lax password reuse and the rise of automated credential testing tools.

A joint probe by the UK and Canadian privacy authorities uncovered a troubling pattern of negligence.

Despite growing industry consensus around multi-factor authentication (MFA) as a baseline standard, 23andMe had not implemented it.

Investigators also flagged the company’s slow reaction to a massive login attempt targeting one million accounts in a single day during July 2023, a missed red flag that could have limited the scope of the breach.

UK Information Commissioner John Edwards criticized the firm’s lack of preventative action, stressing the uniquely permanent nature of genetic data. “The exposed information was profoundly damaging,” he said. “Unlike passwords or credit card numbers, this type of personal data cannot be changed or reissued once compromised.”

The ICO’s decision to impose the maximum allowable fine reflects the seriousness of 23andMe’s security lapses.

It also signals a broader shift in regulatory posture, as UK data authorities bolster oversight of biometric and genetic data.

If you’re tired of censorship and dystopian threats against civil liberties, subscribe to Reclaim The Net.

The post UK Fines 23andMe $3.1M Over Major Genetic Data Breach appeared first on Reclaim The Net.

Views: 0
Please follow and like us:
About Steve Allen 2493 Articles
My name is Steve Allen and I’m the publisher of ThinkAboutIt.online. Any controversial opinions in these articles are either mine alone or a guest author and do not necessarily reflect the views of the websites where my work is republished. These articles may contain opinions on political matters, but are not intended to promote the candidacy of any particular political candidate. The material contained herein is for general information purposes only. Commenters are solely responsible for their own viewpoints, and those viewpoints do not necessarily represent the viewpoints of the operators of the websites where my work is republished. Follow me on social media on Facebook and X, and sharing these articles with others is a great help. Thank you, Steve

Be the first to comment

Leave a Reply

Your email address will not be published.




This site uses Akismet to reduce spam. Learn how your comment data is processed.