• News
    • Tech News
    • AI
  • Gadgets
    • Apple
    • iPhone
  • Gaming
    • Playstation
    • Xbox
  • Science
    • News
    • Space
  • Streaming
    • Netflix
  • Vehicles
    • Car News
  • Social Media
    • WhatsApp
    • YouTube
  • Advertise
  • Terms
  • Privacy & Cookies
  • LADbible Group
  • LADbible
  • UNILAD
  • SPORTbible
  • GAMINGbible
  • Tyla
  • FOODbible
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Topics A-Z
  • Authors
Facebook
Instagram
X
TikTok
Snapchat
WhatsApp
Submit Your Content
23andMe fined for failing to protect users' data in cyber attack following investigation

Home> News

Published 16:55 17 Jun 2025 GMT+1

23andMe fined for failing to protect users' data in cyber attack following investigation

A data breach at the genetic testing company exposed users' personal information

Rikki Loftus

Rikki Loftus

DNA testing company 23andMe has been fined for failing to protect its users' data in a cyber attack that took place in 2023.

This comes after an investigation was conducted by the UK’s Information Commissioner’s Office (ICO) determined that the firm had failed to ‘implement appropriate security measures to protect the personal information of UK users, following a large-scale cyber attack in 2023’.

As a result, 23andMe has been fined a penalty of £2.31 million ($3.12 million) after a hacker was able to gain unauthorized access to the personal information of over 150,000 UK customers.

This information included things such as names, postcodes, birth years, images, ethnicity, family trees and health reports.

Advert

John Edwards, who is the UK Information Commissioner, said: “This was a profoundly damaging breach that exposed sensitive personal information, family histories, and even health conditions of thousands of people in the UK. As one of those impacted told us: once this information is out there, it cannot be changed or reissued like a password or credit card number.

The UK watchdog found that 23andMe failed to protect its users data (Westend61/Getty Images)
The UK watchdog found that 23andMe failed to protect its users data (Westend61/Getty Images)

“23andMe failed to take basic steps to protect this information. Their security systems were inadequate, the warning signs were there, and the company was slow to respond. This left people’s most sensitive data vulnerable to exploitation and harm.

“We carried out this investigation in collaboration with our Canadian counterparts, and it highlights the power of international cooperation in holding global companies to account. Data protection doesn’t stop at borders, and neither do we when it comes to protecting the rights of UK residents.”

Advert

In total, the ICO received 12 complaints from 23andMe users, with one anonymous person impacted by the data breach saying: “I expected rigorous privacy controls to be in place due to the nature of the information collected. Unlike usernames, passwords and email addresses, you can't change your genetic makeup when a data breach occurs.”

Another wrote: “Disgusted that my DNA data could be out there in the wild and been exposed to bad actors. Extremely anxious about what this could mean to my personal, financial and family safety in the future. Anxious about my 23andme connections, who may have been impacted and what this may mean further down the line for me.”

23andMe has been hit with a huge fine (Tayfun Coskun/Anadolu via Getty Images)
23andMe has been hit with a huge fine (Tayfun Coskun/Anadolu via Getty Images)

What can you do to strengthen your own cybersecurity?

If you’re worried that your own data might be vulnerable online then there are steps you can take in order to protect yourself.

Advert

First off, make sure you’re using a strong and unique password for each account you open and be sure to enable two-factor authentication when possible.

Be alert for any phishing emails and scam messages which you can report and delete.

Featured Image Credit: Tayfun Coskun/Anadolu via Getty Images
Cybersecurity
Health
Science
DNA
News
World News

Advert

Advert

Advert

Choose your content:

a day ago
  • a day ago

    Swarm of angry jellyfish force nuclear power plant to immediately shut down

    Nuclear energy gets its latest detractor

    News
  • a day ago

    Humanoid robots found violently beating each other in underground robot 'fight club'

    Hopefully they're also aware of the first rule

    News
  • a day ago

    Archaeologists uncover mysterious 2,000-year-old coin that could link to Jesus' biblical prophecy

    It links to a major moment in ancient history

    News
  • a day ago

    Google announces $9,000,000,000 investment into Oklahoma

    Google's AI push has taken them to southern state

    News
  • Millions of iPhone users warned to update immediately following 'extremely sophisticated attack'
  • Facebook users urged to check their bank account after 1,200,000,000 users' data is stolen in historic breach
  • Google Chrome users urged to clear browsing data immediately amid 'red alert' warning
  • Urgent warning issued to 1,800,000,000 Gmail users following ‘sophisticated’ password hack