Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

23andMe Faces £2.31 Million Fine From ICO for Insufficient Data Security

by Jane Doe
June 23, 2025
in Cyber
A A
0
Share on FacebookShare on Twitter

Genetic testing giant 23andMe has been slapped with a £2.31 million fine by the UK’s Information Commissioner’s Office (ICO) following a “profoundly damaging” data breach in 2023 that exposed the highly sensitive personal and genetic data of over 155,000 UK residents. The penalty, announced last week, underscores significant failings in the company’s data security protocols and its sluggish response to the cyberattack.

The ICO, in a joint investigation with Canada’s Office of the Privacy Commissioner, found that 23andMe breached UK data protection law by failing to implement adequate technical and organizational measures to safeguard user data. Key deficiencies identified included a lack of mandatory multi-factor authentication (MFA), weak password protocols, and insufficient systems for monitoring and detecting cyber threats. Crucially, the company also failed to implement additional verification steps for users attempting to access and download their raw genetic data, leaving this extremely sensitive information vulnerable.

The breach, a “credential stuffing” attack, began in April 2023 and continued until September of the same year. Attackers exploited login credentials stolen from unrelated previous data breaches to gain unauthorized access to 23andMe accounts. While only a small percentage of accounts were directly accessed, the company’s “DNA Relatives” feature meant that the compromise of approximately 14,000 accounts ultimately exposed the data of around 6.9 million individuals globally, including the affected UK residents.

Information Commissioner John Edwards heavily criticized 23andMe’s response, highlighting that the company was slow to react despite early warning signs. A full investigation was only initiated in October 2023, after an employee discovered the stolen data being advertised for sale on Reddit – months after the initial infiltration. “This was a profoundly damaging breach that exposed sensitive personal information, family histories, and even health conditions of thousands of people in the UK,” Edwards stated. “Once this information is out there, it cannot be changed or reissued like a password or credit card number.”

Read Also

Global Connected Car Regulations Analysis Report 2025: Focus on Cybersecurity and Data Privacy

Black Hat SEO Poisoning Search Engine Results For AI

While the fine was reduced from an initial proposed amount of £4.59 million due to 23andMe’s recent bankruptcy filing in the US, the ICO maintained that a substantial penalty was necessary to ensure an effective and dissuasive response to the breaches. The ruling serves as a stark warning to organizations handling sensitive personal data, emphasizing the critical importance of robust cybersecurity practices and prompt incident response. 23andMe has reportedly implemented security enhancements since the breach, including making MFA a default setting.

Jane Doe

You May Also Likes!

Iranian-backed hackers go to work after U.S. strikes
Cyber

Cyber is now the third-largest economy in the world – June 2025 Report

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

DHS warns of heightened cyber threat as US enters Iran conflict

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Leak of data belonging to 7.4 million Paraguayans traced back to infostealers

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Billions of login credentials have been leaked online, Cybernews researchers say

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Global cyber alert: Iranian hackers strike U.S. banks, defence and oil firms

by Jane Doe
June 25, 2025
Load More

Recommended

Enhance Your Cybersecurity on World Environment Day with KnowBe4’s Expert Guide

Enhance Your Cybersecurity on World Environment Day with KnowBe4’s Expert Guide

June 5, 2025
AI Security Risks Are Not Theoretical: They’re Happening Now

AI Security Risks Are Not Theoretical: They’re Happening Now

May 27, 2025
New Windows RAT Exploits Corrupted Headers for Stealthy Evasion

New Windows RAT Exploits Corrupted Headers for Stealthy Evasion

May 31, 2025
Hacking AI the Right Way: A Guide to AI Red Teaming

Hacking AI the Right Way: A Guide to AI Red Teaming

May 27, 2025
Iranian-backed hackers go to work after U.S. strikes

Global Connected Car Regulations Analysis Report 2025: Focus on Cybersecurity and Data Privacy

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

Black Hat SEO Poisoning Search Engine Results For AI

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

Cyber is now the third-largest economy in the world – June 2025 Report

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

DHS warns of heightened cyber threat as US enters Iran conflict

June 25, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.