23andMe hit with £2.3M fine after exposing genetic data of millions
ID: 2b43fef5-9c5c-5019-8bde-85213179a771
STIX ID: report--2b43fef5-9c5c-5019-8bde-85213179a771
Feed Name: The Register (Security)
Threat Score
23andMe experienced a 2023 credential-stuffing breach that accessed roughly 14,000 accounts and — via its DNA Relatives feature — exposed personal, health, and genetic data for about 6.9 million users; UK and Canadian regulators found inadequate authentication (no mandatory MFA), insufficient controls to prevent bulk data access, and poor monitoring/response, leading to a £2.31M ICO fine and the company's later Chapter 11 bankruptcy proceedings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
