UK and Canada privacy watchdogs investigating 23andMe data breach

Date:

Share post:


Privacy watchdogs in the U.K. and Canada have launched a joint investigation into the data breach at 23andMe last year. 

On Monday, the U.K,’s Information Commissioner’s Office (ICO) and the Office of the Privacy Commissioner of Canada (OPC) announced their investigation into the genetic testing company, saying the organizations will leverage “the combined resources and expertise of their two offices.” 

Last year, 23andMe disclosed a security incident that affected the genetic and ancestry data of 6.9 million users, or roughly half of its overall user base. In its data breach notices, the company said it didn’t detect the hackers’ activities for around five months, from April until September 2023. 23andMe said it only became aware of the account breaches in October 2023, when hackers advertised the stolen data on the unofficial 23andMe subreddit and a well-known hacking forum. 

The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports, and self-reported location.

Hackers broke into around 14,000 accounts of 23andMe customers by reusing their passwords from previous breaches, a technique known as password spraying. From those 14,000 accounts, the hackers were able to scrape information on millions of other people because of an opt-in feature called the DNA Relatives, which allowed users to automatically share some of their data with other people who also had opted-in, with the goal of uncovering far-away relatives. That’s how the hackers were able to scrape information on 6.9 million users by only hacking 14,000 accounts. 

In a statement, ICO Commissioner John Edwards was quoted as saying that people “need to trust that any organisation handling their most sensitive personal information has the appropriate security and safeguards in place.” 

“This data breach had an international impact, and we look forward to collaborating with our Canadian counterparts to ensure the personal information of people in the U.K. is protected,” said Edwards. 

The joint U.K.-Canada investigation will look into the scope of information exposed and the potential harm to the victims; whether 23andMe “had adequate safeguards” to protect users’ sensitive data; and whether 23andMe “provided adequate notification” to the ICO and the OPC. 

23andMe spokespeople did not immediately respond to a request for comment.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Spain’s exposure to climate change helps Madrid-based VC, Seaya, close €300M climate-tech fund

According to a recent Dealroom report on the Spanish tech ecosystem, the combined enterprise value of Spanish...

Forestay, Europe’s newest $220M growth-stage VC fund, will focus on AI

Forestay, an emerging VC based out of Geneva, Switzerland has been busy. This week it closed its...

A year later, what Threads could learn from other social networks

Threads, Meta’s alternative to Twitter, just celebrated its first birthday. After launching on July 5 last year,...

J2 Ventures, focused on military healthcare, grabs $150M for its second fund

J2 Ventures, a firm led mostly by the U.S. military veterans, announced on Thursday that it has...

HealthEquity says data breach is an ‘isolated incident’

On Tuesday, health tech services provider HealthEquity disclosed in a filing with federal regulators that it had...

Roll20, an online tabletop role-playing game platform, discloses data breach

The popular online tabletop and role-playing game platform Roll20 announced on Wednesday that it had suffered a...

Fizz, the anonymous Gen Z social app, adds a marketplace for college students

Teddy Solomon just moved to a new house in Palo Alto, so he turned to the Stanford...

Deep tech VC Sidney Scott explains why he’s closing his firm as this area booms

Sidney Scott decided to take himself out of the venture capital rat race and is now jokingly...