Genetics testing company 23andMe to be probed over a data breach that affected 7 million users – E&T Magazine

Posted: June 17, 2024 at 2:44 am

Data protection watchdogs in Canada and the UK have announced a joint investigation into a data breach at genetics testing company 23andMe that affected seven million customers in 2023.

Since 2006, San Francisco-based genetic testing company 23andMe has sold over 12 million DNA testing kits. It analyses customers saliva to provide insights into health and ancestry.

In October 2023, 23andMe reported a security breach in which hackers gained access to the personal information of millions of customers by using old passwords. In some cases, the information accessed included family trees, birth years and geographic locations.

The Information Commissioner's Office (ICO) in the UK and the Office of the Privacy Commissioner of Canada (OPC) will examine the scope of information that was exposed by the breach and potential harms to affected people.

John Edwards, the UK information commissioner, said: People need to trust that any organisation handling their most sensitive personal information has the appropriate security and safeguards in place.

He added: This data breach had an international impact, and we look forward to collaborating with our Canadian counterparts to ensure the personal information of people in the UK is protected.

The strength of 23andMes safeguards to protect the information within its control will also be investigated, as well as whether the company provided adequate notification about the breach to the two regulators and affected people.

Philippe Dufresne, the Canadian privacy commissioner, said: In the wrong hands, an individuals genetic information could be misused for surveillance or discrimination. Ensuring that personal information is adequately protected against attacks by malicious actors is an important focus for privacy authorities in Canada and around the world.

According to the Guardian, a 23andMe spokesperson had previously said that the company did not detect a breach within its systems and instead attributed the incident to compromised recycled login credentials from certain users.

However, 23andMe has said it will cooperate with the investigation and the regulators reasonable requests.

Read the rest here:
Genetics testing company 23andMe to be probed over a data breach that affected 7 million users - E&T Magazine

Related Posts

Comments are closed.

Archives