[ad_1]
The UK and Canadian privacy authorities have commenced a collaborative investigation into 23andMe’s data security breach disclosed last year.
The Information Commissioner’s Office (ICO) of the UK and the Office of the Privacy Commissioner of Canada (OPC) jointly announced on Monday their probe into the genetic testing firm, aiming to utilize their collective capabilities and knowledge.
In 2023, 23andMe made public a breach that impacted approximately 6.9 million users, constituting about half its customer base. The notifications regarding the breach clarified that the intrusion went unnoticed for a duration of approximately five months, from April to September 2023. The cybercriminals’ actions were only unearthed in October 2023 when the stolen information was advertised on the unofficial 23andMe subreddit and a notorious hacking forum.
Compromised data encompassed names, the year of birth, relationship descriptors, proportions of shared DNA with relations, ancestry insights, and user-reported locations.
Password spraying—a method where reused passwords from past breaches are utilized—was employed by hackers to access about 14,000 23andMe accounts. Once inside, they harnessed an opt-in feature, DNA Relatives, designed to reveal distant family connections by sharing data with others who had also opted in. This allowed the attackers to extend their breach to information on a total of 6.9 million individuals by penetrating only 14,000 accounts.
John Edwards, ICO Commissioner, stated that the public expects robust security measures from organizations managing especially sensitive data.
“With its global implications, this breach warrants our working closely with the Canadian authority to defend UK citizens’ personal information,” Edwards commented.
This UK-Canada investigation intends to ascertain the exposed data’s extent, evaluate the potential damage to the victims, appraise whether 23andMe held “adequate safeguards” for user information, and determine the sufficiency of the breach notification provided to the ICO and the OPC.
Requests for comment from 23andMe representatives were not immediately addressed.
[ad_2]
Frequently Asked Questions (FAQ)
What led to the data breach at 23andMe?
Hackers utilized a common technique known as password spraying, wherein they gained access to around 14,000 accounts using passwords leaked from unrelated breaches.
How many users were affected by the 23andMe breach?
The breach impacted 6.9 million users, roughly amounting to half of the company’s user base at the time.
What types of data were compromised in the 23andMe breach?
Compromised data included names, birth years, relationship labels, percentage of DNA shared with relatives, ancestry reports, and self-reported locations of users.
Who is investigating the 23andMe data breach?
The Information Commissioner’s Office (ICO) in the UK and the Office of the Privacy Commissioner of Canada (OPC) are jointly conducting the investigation.
The two authorities will examine the breath of the information that was exposed, assess the potential harm to those affected, and determine if 23andMe had the proper safeguards and provided adequate notification regarding the breach.










































