Loading stock data...

QuantumIntelligence

An in-depth look at the combination of quantum computing and artificial intelligence

23andme data breach cybersecurity getty 1
Technology

Genetic Testing Company 23andMe Confirms Hackers Stole Ancestry Data of Over 6.9 Million Users

On Friday, genetic testing company 23andMe announced that hackers accessed the personal data of 0.1% of its customers, approximately 14,000 individuals. However, as the situation unfolded, it became clear that the actual number of affected individuals was significantly higher.

The Initial Disclosure: A Fraction of the Truth

When 23andMe first disclosed the breach in early October, they stated that hackers accessed a "significant number" of files containing profile information about other users’ ancestry. However, they refused to provide any specific numbers or details regarding the extent of the breach.

The New Numbers: A Devastating Reality

In an email sent to TechCrunch late on Saturday, 23andMe spokesperson Katie Watson confirmed that hackers accessed the personal information of approximately 5.5 million people who opted-in to 23andMe’s DNA Relatives feature. This feature allows customers to automatically share some of their data with others.

The stolen data included:

  • Personal information: The person’s name, birth year, and self-reported location.
  • Ancestry reports: A detailed breakdown of the individual’s ancestry.
  • DNA shared with relatives: The percentage of DNA shared between the account holder and their relatives.
  • Relationship labels: Information regarding the relationships between the account holder and their relatives.

Furthermore, 23andMe confirmed that another group of approximately 1.4 million people who opted-in to DNA Relatives had their Family Tree profile information accessed. This included:

  • Display names: The display name associated with the user’s account.
  • Relationship labels: Information regarding the relationships between the account holder and their relatives.
  • Birth year: The birth year of the account holder.
  • Self-reported location: The self-reported location of the account holder.

The Extent of the Breach: A Shocking Reality

Considering the new numbers, it is clear that the data breach affects roughly half of 23andMe’s total reported 14 million customers. This means that approximately 6.9 million individuals have had their personal information compromised in the breach.

The Hacker’s Claim: A Trail of Evidence

In early October, a hacker claimed to have stolen the DNA information of 23andMe users in a post on a well-known hacking forum. As proof of the breach, the hacker published the alleged data of one million users of Jewish Ashkenazi descent and 100,000 Chinese users. The hacker asked would-be buyers for $1 to $10 per individual account.

Two weeks later, the same hacker advertised the alleged records of another four million people on the same hacking forum. TechCrunch found that another hacker on a separate hacking forum had already advertised a batch of allegedly stolen 23andMe customer data two months before the widely reported advertisement.

The Authenticity of the Leaked Data: A Concern

TechCrunch’s investigation revealed that the leaked data was indeed authentic, raising serious concerns about the security measures in place at 23andMe. The fact that hackers were able to access sensitive information from millions of users highlights a significant vulnerability in the company’s systems.

A Devastating Blow: The Consequences of the Breach

The 23andMe data breach has sent shockwaves throughout the genetic testing industry, leaving many customers concerned about their personal information. As the situation continues to unfold, it is clear that this breach will have far-reaching consequences for both individuals and the company itself.

A Lesson Learned: The Importance of Data Security

This incident serves as a stark reminder of the importance of robust data security measures in today’s digital age. Companies handling sensitive information must prioritize the protection of their customers’ data, implementing robust safeguards to prevent such breaches from occurring.

The Road Ahead: A Commitment to Transparency and Security

As 23andMe navigates this challenging situation, it is essential that they commit to transparency and security. The company must work tirelessly to address the vulnerabilities in their systems, providing regular updates on the progress of their efforts.

Furthermore, 23andMe must prioritize the protection of its customers’ data, implementing measures to prevent similar breaches from occurring in the future. This may involve investing in advanced security technologies, enhancing user education, and fostering a culture of security within the organization.

A New Era: A Chance for Redemption

In the wake of this devastating breach, 23andMe has an opportunity to emerge stronger and more resilient than ever before. By prioritizing transparency, security, and customer trust, the company can rebuild its reputation and establish itself as a leader in the genetic testing industry.

The road ahead will be challenging, but with determination and a commitment to excellence, 23andMe can overcome this setback and continue to provide valuable services to its customers.