Federal privacy commissioner Philippe Dufresne and U.K. information commissioner John Edwards spoke to reporters during a press conference held at Ottawa’s National Press Theatre on Tuesday, June 17, 2025. (Photo credit: Sean Kilpatrick / The Canadian Press)


June 19, 2025 Tags:

A major security lapse at genetic testing firm 23andMe led to the exposure of sensitive personal data from nearly seven million customers — a breach that could have been avoided, according to a joint investigation by Canadian and U.K. privacy watchdogs.

On Tuesday, Canada’s Privacy Commissioner Philippe Dufresne and U.K. Information Commissioner John Edwards revealed findings from their year-long investigation into the breach. It affected about 6.9 million users, including 320,000 Canadians.

Dufresne warned the public that this breach is a stark reminder of how vital strong digital security is. “It’s a lesson for every organization handling personal data in today’s digital age,” he said during a press briefing.

23andMe, known for its DNA testing kits that analyze customers' saliva to trace ancestry and health traits, filed for bankruptcy earlier this year. The investigation revealed the breach was caused by weak internal safeguards, allowing hackers to exploit reused passwords from other online leaks.

Sensitive details like customers’ health data, racial and ethnic backgrounds, birthdates, gender identity, and even information about relatives were compromised. What made it worse was that some of this data later ended up for sale online, increasing the risk of identity theft or misuse.

The breach began on April 29, 2023, and lasted five months. Hackers gained access to more than 18,000 customer accounts by using previously stolen login credentials from other websites. Once inside, they accessed not only the account holders' information but also details of their genetic relatives, due to an optional sharing feature on 23andMe’s platform. As a result, data from millions more individuals became vulnerable.

The report stated that 23andMe had failed to adopt even basic cybersecurity measures. It didn’t require users to set complex passwords, nor did it mandate two-step authentication, which is now standard across many digital platforms. The company also didn’t check whether customers’ passwords had been leaked in earlier data breaches elsewhere.

More alarmingly, there were no extra protections for extremely sensitive content like raw DNA data — information that could potentially be misused for medical, legal, or insurance reasons.

The investigation also found that 23andMe’s internal security systems did not flag any unusual activity even as hackers were clearly working their way into thousands of accounts. Despite recognizing the attack as it was happening, it took the company four days to log out users and force password resets. It took another month to shut down the raw DNA download option and finally implement two-factor authentication.

Privacy commissioners in both countries emphasized that organizations must do better — especially those handling deeply personal information like genetic data. Stronger digital protections, faster response times, and better detection systems are no longer optional, they said — they are essential.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

Cheap Laptops Challenge MacBook Neo With More Storage and Memory

Apple has stepped into the budget laptop segment with the launch of the MacBook Neo, priced at $599. On paper,....

Apple iPhone 17e Leads Apple Product Launch Week With M4 iPad Air Update

Apple has kicked off a fresh round of hardware announcements with a clear focus on value and performance. The company....

Viral AI Caricature Trend Sparks Serious Privacy Fears, Expert Warns

A viral social media trend that turns personal details into AI-generated caricatures is raising red flags among cybersecurity experts, who....

India AI Impact Summit 2026: Global Leaders, CEOs Gather in New Delhi for High-Stakes Talks

India has opened a major global gathering focused on artificial intelligence and its growing worldwide influence. The India AI Impact....

PlayStation State of Play February 2026: Biggest Announcements and Games Revealed

One week after Nintendo set the tone for 2026, PlayStation stepped forward with its own showcase. The PlayStation State of....

Bell AI Data Centre Near Regina Signals Major Tech Investment in Saskatchewan

Bell Canada is planning a major expansion of artificial intelligence infrastructure near Regina, according to newly filed municipal documents.The project....

Moltbook: Experts Flag Security Risks on Viral AI Forum

A strange new social platform has captured the internet’s curiosity — and concern. Moltbook, a social forum designed exclusively for....

Global Software Stocks Slide as AI Fears Trigger ‘SaaSpocalypse’

A global sell-off in software stocks is accelerating as investors grow increasingly anxious about how fast artificial intelligence could upend....

Experts Find Rare Space Molecule Hints at Life Origins of Past Life

Scientists have identified the largest organic molecule containing sulfur ever found in interstellar space, a discovery that may help explain....

NASA updates Artemis II wet dress test and launch windows soon

NASA has moved the timeline for a key Artemis II test because of severe winter weather in Florida. The agency....

Meta Blocks Teens From AI Characters Ahead of Child Safety Trial

Meta is temporarily revoking teen access to its AI characters as scrutiny over tech platforms and child safety intensifies. The....

NASA Astronaut Sunita Williams Retires After 9-Month Orbital Ordeal

NASA astronaut Sunita Williams has announced her retirement, marking the end of a remarkable 27-year career in space exploration. Her....