logo

UK and Canada's data chiefs join forces to investigate 23andMe mega-breach

ID: 58d08d70-7c91-508a-8485-a371444d289c

STIX ID: report--58d08d70-7c91-508a-8485-a371444d289c

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Regulators in the UK (ICO) and Canada (OPC) have opened a joint investigation into 23andMe's October 2023 credential-stuffing breach, which directly accessed ~14,000 accounts but — due to the platform's DNA Relatives opt‑in and complex privacy settings — resulted in exposure of data tied to nearly 7 million users; the attacker known as "Golem" published the stolen data and made targeted, anti‑Semitic statements. The report highlights failures in detection (five months before discovery via a Reddit post), the late enabling of default 2FA in November 2023, and ensuing debate over customer security practices and the company’s communications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.