Many people's genetic data is on the Dark Web due to 23andMe breach

An anonymous hacker is claiming to be selling millions of genetic profiles from hacked 23andMe customer accounts.

Genealogy services can tell you a lot, but they also require you to hand over some very sensitive personal data. Having your genetic data sold on the dark web is no joke. Thanks to this genealogy service data breach, that's exactly what's happening.

 

Users' genetic data is being sold online

DNA testing company 23andMe suffered a massive data breach in 2023 that exposed the genetic data of millions of customers. Hackers were able to compromise 14,000 personal accounts and steal information related to approximately 6.9 million individuals listed as potential relatives on the site.

Stolen data includes:

 

  • Name
  • Date of birth
  • Geographic information
  • Profile photo
  • Race
  • Health report
  • Nation
  • Genealogy

Following the data breach, the UK Information Commissioner's Office (ICO) and Canada's Office of the Privacy Commissioner (OPC) announced a joint investigation into the incident in June 2024. A year later, the investigation concluded with a £2.31 million ($3.13 million) fine against 23andMe for what the ICO described as a "serious breach."

 

The investigation also highlighted security lapses at the time of the breach. The company failed to implement proper authentication measures, with a lack of mandatory multi-factor authentication (MFA) and lax password requirements. 23andMe also failed to take steps to prevent access to and download of raw genetic data, and did not have 'effective systems to monitor, detect, or respond to cyber threats targeting sensitive customer information . '

John Edwards, UK Information Commissioner, explains:

23andMe failed to take basic steps to protect this information. Their security systems were inadequate, the warning signs were there, and the company was slow to respond. This left people's most sensitive data vulnerable to exploitation and harm.

23andMe's lackadaisical approach to acknowledging the breach has also been pointed out. The first breach began in April 2023 and lasted until May 2023. However, the company did not acknowledge the breach and launch a full investigation until October 2023, when an employee discovered the stolen data being sold on Reddit.

Data protection starts with you

Unlike passwords and other information that often gets leaked in such data breaches, you can't just change your genetic data. Once it's public, you're essentially compromised for life.

So while there's not much you can do in this case other than be vigilant for any phishing or identity theft attempts, you can still try to protect yourself from future breaches. Setting up MFA for your online accounts and using strong, unique passwords for each account are some of the most basic steps you should take to protect your digital footprint, regardless of whether your service provider requires it or not. It's also important to protect your credit rating if you're affected by a data breach.

Also, try to avoid using online services that ask for too much sensitive information in the first place. Sure, learning about your ancestors may sound interesting, but that curiosity is not worth risking extremely sensitive genetic information that could be used for all sorts of nefarious purposes.

Other Technology story articles
Category

System

Windows XP

Windows Server 2012

Windows 8

Windows 7

Windows 10

Wifi tips

Virus Removal - Spyware

Speed ​​up the computer

Server

Security solution

Mail Server

LAN - WAN

Ghost - Install Win

Fix computer error

Configure Router Switch

Computer wallpaper

Computer security

Mac OS X

Mac OS System software

Mac OS Security

Mac OS Office application

Mac OS Email Management

Mac OS Data - File

Mac hardware

Hardware

USB - Flash Drive

Speaker headset

Printer

PC hardware

Network equipment

Laptop hardware

Computer components

Advice Computer

Game

PC game

Online game

Mobile Game

Pokemon GO

information

Technology story

Technology comments

Quiz technology

New technology

British talent technology

Attack the network

Artificial intelligence

Technology

Smart watches

Raspberry Pi

Linux

Camera

Basic knowledge

Banking services

SEO tips

Science

Strange story

Space Science

Scientific invention

Science Story

Science photo

Science and technology

Medicine

Health Care

Fun science

Environment

Discover science

Discover nature

Archeology

Life

Travel Experience

Tips

Raise up child

Make up

Life skills

Home Care

Entertainment

DIY Handmade

Cuisine

Christmas

Application

Web Email

Website - Blog

Web browser

Support Download - Upload

Software conversion

Social Network

Simulator software

Online payment

Office information

Music Software

Map and Positioning

Installation - Uninstall

Graphic design

Free - Discount

Email reader

Edit video

Edit photo

Compress and Decompress

Chat, Text, Call

Archive - Share

Electric

Water heater

Washing machine

Television

Machine tool

Fridge

Fans

Air conditioning

Program

Unix and Linux

SQL Server

SQL

Python

Programming C

PHP

NodeJS

MongoDB

jQuery

JavaScript

HTTP

HTML

Git

Database

Data structure and algorithm

CSS and CSS3

C ++

C #

AngularJS

Mobile

Wallpapers and Ringtones

Tricks application

Take and process photos

Storage - Sync

Security and Virus Removal

Personalized

Online Social Network

Map

Manage and edit Video

Data

Chat - Call - Text

Browser and Add-on

Basic setup