
23andMe fined millions by UK watchdog over 'profoundly damaging' cyber attack
The genetic testing company 23andMe is being fined £2.31m by the UK's privacy watchdog over their 2023 data breach that saw the personal information of seven million people stolen.
More than 150,000 Britons had their personal information taken by hackers. Family trees, health reports, race and ethnicity information may all have been stolen, along with addresses, dates of birth and profile pictures.
A database shared on dark web forums and viewed by Sky News' US partner network, NBC News, contained a list of 999,999 people who allegedly had Ashkenazi Jewish heritage, according to 23andMe's genetic profiling.
"Crazy. This could be used by Nazis," said one person at the time who appeared in the database.
The ICO's fine comes after a joint investigation with Canada's privacy watchdog.
It is the most severe punishment the watchdog can impose and reflects repeated failures to protect extremely sensitive data, according to the information commissioner.
"This was a profoundly damaging breach that exposed sensitive personal information, family histories, and even health conditions of thousands of people in the UK," said John Edwards, the UK's Information Commissioner.
"23andMe failed to take basic steps to protect this information.
"Their security systems were inadequate, the warning signs were there, and the company was slow to respond. This left people's most sensitive data vulnerable to exploitation and harm."
Despite the attack starting in April 2023, 23andMe did not open an investigation until October that year, when an employee discovered the stolen data had been advertised for sale on Reddit.
The company's defences only became strong enough to halt the attack by the end of that year - but that was not the end of 23andMe's troubles.
'Sue you to oblivion'
By March this year, the best-known genetic testing company in the world had filed for bankruptcy, unable to rebuild trust after the hack and make enough money from its business model.
It will now be sold for $305m (£225m) to 23andMe's original co-founder, Anne Wojcicki and her non-profit TTAM.
But a blistering exchange in the US Senate last week laid out fresh concerns for the sensitive data users have shared with 23andMe.
Senator Josh Hawley accused Joseph Selsavage, the interim chief executive of 23andMe, of lying to his customers when he says they can delete their genetic data from the company's databases.
"You're not deleting it," he said, "because if you were, your company wouldn't be worth $300m."
"I hope [users] will rush to the courthouse [...] to sue you into oblivion."
Mr Selsavage denied Senator Hawley's claims, saying his company deletes all user data when requested.
James Moss, the director of cyber investigations at law firm Addleshaw Goddard, told Sky News the ICO's fine was "about as serious as it gets" but an enforcement order, a notice from the watchdog that dictates how data can be used in the future, would be "more important".
"That's the notice which looks forward and says, 'look, you have a legal obligation under UK law to continue to protect the personal data of these 150,000 UK citizens'. And that's arguably the more important," he said.
A total of 28 US attorneys general last week launched a legal case against 23andMe to protect user data during the sale, and urged customers to purge their information from the firm's database, given the sensitivity of the data it has collected over the years.
23andMe already sells its users' genetic data and has made at least 30 deals with biotech and pharmaceutical companies like GSK.
A spokesperson for the 23andMe buyer, TTAM, told Sky News the non-profit had made "several binding commitments to enhance protections for customer data and privacy".
These include allowing individuals to delete their account and opt out of research at any time, notifying customers at least two days before the deal closes about what TTAM's acquisition means for them and agreeing, if TTAM were to sell the company again, only to sell it to someone who agrees to adopt TTAM's privacy polices and comply with data laws.
Customers will also be offered two years of free Experian identity theft monitoring, while TTAM will continue to allow "de-identified data" to be used for scientific and biomedical research at universities and nonprofits.
No money for UK victims
The £2.31m fine money will go to the state rather than to individuals affected by the hack.
In the US, victims of the hack won $30m in a class action lawsuit last year, but that's not an option in the UK, despite the incredibly sensitive information that was shared.
Class action lawsuits for data breaches could "improve and increase accountability for data-protection breaches", according to solicitor Alex Lawrence Archer from the data law agency AWO.
"But also help individuals who are affected get something back, help them get redress, because a fine paid to the ICO doesn't achieve that. Although [the fine] is welcome, it doesn't help individuals."
For anyone thinking about using one of the many genetic testing companies that have sprung up since 23andMe was founded in 2006, Mr Lawrence Archer has cautionary advice.
"Handing over your genetic data is a really big step, and it's something that [...] people have hitherto been encouraged to take quite lightly," he said.
"There's no hard and fast rule like you should or you shouldn't do it, but it's something that you should think really carefully about.
"It can be a quite permanent step that's very difficult to undo. It's not something that should be done lightly."

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Sky News
14 minutes ago
- Sky News
Bosses of Octopus Energy and SSE clash over 'postcode pricing' proposals
The head of Britain's biggest energy supplier has claimed his competitors oppose proposals for so-called postcode pricing because they financially benefit from the current system. Octopus Energy chief executive Greg Jackson told Sky News his business's rivals were against customers being charged based on where they lived, rather than on a national basis, because they would lose out on profits. He said: "A very small number of companies that today get paid tens of millions, sometimes in a single day, to turn off wind farms and generate gas elsewhere, don't like it. "The reason you're seeing that kind of behaviour from the rivals is they are benefiting from the current system that's generating incredible profitability." The government is currently considering whether to introduce the policy, which is also known as zonal pricing. Energy secretary Ed Miliband is expected to make a decision on the proposals by this summer. Octopus has become Britain's biggest supplier with more than seven million customers. Mr Jackson has been a vocal proponent, as he said he wants to charge customers less and boost government electrification policies by having cheaper electricity costs. What is postcode pricing? Zonal pricing would mean electricity bills are based on what region you live in. Some parts of Britain, like northern Scotland, are home to huge energy producers in the form of offshore wind farms. But rather than feeding electricity to local homes and businesses, power goes into a nationwide auction and is bought to go across Britain. As the energy grid is still wired for the old coal-producing sites rather than the modern renewable generators, it's not straightforward to get electricity from where it's increasingly produced to the places people live and work. That leads to traffic jams on the grid, blocking paid-for electricity moving to where it's needed and a system where producers can be paid a second time, to power down, and other suppliers, often gas plants, are paid to meet the shortfall. Zonal pricing is designed to prevent paying the generators for power that can't be used. It would mean those in Scotland have lower wholesale energy costs while those in the south, where there is less renewable energy production, would have higher wholesale costs. Whether bills go up or down depends on implementation. Savings from one region could be spread across Britain, lowering bills across the board. Mr Miliband has said he's not going to decide to raise prices. However, SSE's chief executive Alistair Phillips-Davies described the policy as a "distraction" and said it could affect already agreed-upon upgrades of the national grid that will lower costs. "I think you've got a very, very small number of people who are asking for this. It's just a distraction. We should remove it now," he said. While Octopus Energy estimates that said postcode pricing could be introduced in two to four years, Mr Phillips-Davies said it could take until 2032 before it was implemented, by which time Britain would have "built much of the networks that are required to get the energy from these places down into the homes and businesses that actually need it". "We just need to stay true to the course," he added. Unions, as well as industry and energy representatives, have also spoken out against the policy. Opponents include eco-tycoon Dale Vince and trade body UK Steel. A joint letter signed by SSE, UK Steel, Ceramics UK and British Glass, along with the unions GMB, Unite and Unison, said zonal pricing could lead to scaled-back investment due to uncertainty and higher bills. A separate letter signed by 55 investors, including Centrica and the Ontario Teachers' Pension Plan, has also criticised the policy. 1:21 However, Mr Jackson said many investors had not voiced opposition, with thousands of small and medium businesses instead backing the policy in the hope of paying less on energy bills.


Daily Mail
14 minutes ago
- Daily Mail
Terrifying moment driver catapults holidaymakers into air after deliberately smashing into them in row over double booked AirBnB rental - as he is jailed
This is the terrifying moment a driver deliberately smashed into two holidaymakers, catapulting them into the air, in a row over a double booked AirBnB rental. Johnathan Newbury, 33, was yesterday jailed for ten years for ploughing his SUV into pedestrians Ryan Jones, 18, and a 17-year-old boy. He had armed himself with a zombie knife and was 'intent on violence' during the car attack in July last year, a court heard. The row broke out after Newbury discovered the AirBnB he had rented for the weekend in Cardiff, Wales, had accidently been double booked. Newbury and his friend Elliott Fiteni, 23, were already inside the property when Mr Jones and the teenager turned up for their own stay. Merthyr Tydfil Crown Court heard Newbury began hurling threats at the pair, shouting 'I'll f*** you up' through a window. He then hunted the men in a black SUV before mowing them down in the street. Prosecutor James Wilson said footage showed the vehicle 'immediately speeding up' and striking two of them as they crossed. Newbury then fled the scene as the victims were left on the ground with serious injuries. Mr Jones suffered injuries to his pelvis and right foot while the teenager lost consciousness and sustained injuries to his jaw, ribs, chest and abdomen. Mr Wilson said the row had started over the booking made in the Cathays area of Cardiff in July of last year where Newbury was due to stay with friend Elliot Fiteni. He said: 'Mr Jones, [...] and another friend had booked an Airbnb on Bruce Street called the Comfortable Stay. 'By chance, a booking had been made at the same address on behalf of Mr Fiteni, who accepted he stayed at the address along with Mr Newbury. 'They were already at the building when Mr Jones and [...] walked towards it.' Newbury, of Cardiff, was found guilty of causing grievous bodily harm with intent, attempting to inflict grievous bodily harm and possession of a bladed article. Judge Jeremy Jenkins Newbury 'You were present at an AirBnB at Bruce Street in Cardiff, the two complainants [...] and Mr Jones had also booked accommodation at the same address and there had been an earlier altercation.' The judge said Newbury had then been part of a group 'armed with what has been described as a zombie knife' and 'intent on violence'. He said: 'The clear aim was to attack [...] and Mr Jones, both ran away from the scene.' Judge Jenkins said Newbury was the driver of the SUV which was 'seen to speed up, to drive on the wrong side of the road into the junction and to deliberately collide with the two men, throwing them up in the air.' Newbury was handed an extended sentence of 10 years and told he must serve at least five years and four months behind bars.


The Guardian
19 minutes ago
- The Guardian
Tighter immigration rules could hit UK net zero mission, report warns
Tough rules announced in the government's immigration white paper could jeopardise the UK's net zero mission by causing labour shortages, a report has warned. Labour's white paper released last month included plans to raise the minimum qualification for skilled worker visas from A-level equivalent to degree and to maintain the higher salary threshold of £38,700 introduced by the outgoing Conservative government last year. A report by the Centre for European Reform (CER), calculates that more than half of the foreign-born workers doing 'green jobs' in the UK – 260,000 out of 465,000 – would not have been allowed in under the new rules. Ministers are relying on employers to raise wages and provide more training in order to attract domestic workers into these roles, but John Springford, an associate fellow at the CER, said that could push up the costs to consumers of going green. 'If labour shortages raise the cost of decarbonising buildings, fewer people will insulate their homes or buy heat pumps,' he said. Using Office for National Statistics data, the CER defined a green job as one in which more than a third of the worker's time is spent on green tasks. Many of these are in the construction sector, given the need to retrofit homes with low-carbon technologies, for example. The report also suggests construction jobs more generally may be difficult to fill under the new visa regime, casting doubt on the government's target to build 1.5m homes by the end of the parliament. 'Construction is labour-intensive and has a lot of employee turnover, because the work is physical and seasonal. Given that the government's aim is to expand housebuilding and decarbonise buildings concurrently, the sector is most at risk of labour shortages as a result of the government's immigration proposals,' the report says. Labour has announced that the existing 'immigration salary list', which allows people doing specific types of job to be brought in on lower pay, will be replaced with a similar 'temporary shortage list'. To avoid this becoming a long-term measure, the relevant industry will be expected to set out plans to train and recruit more UK workers. The CER said that using a shortage list as a safety valve could be problematic because the higher salary threshold elsewhere means migrants in the sectors with shortages are unlikely to be able to shift into other jobs, leaving them vulnerable to exploitation by the employer who sponsors their visa. This problem arose in social care where holders of health and care visas were subject to exploitation by bad employers, with little chance of moving to another post. 'The government should keep an eye on labour shortages in occupations that are crucial for its net zero and housebuilding missions, and relax visa rules if needed,' Springford said. 'But offering exemptions to the rules for specific occupations is risky.' Sign up to Business Today Get set for the working day – we'll point you to all the business news and analysis you need every morning after newsletter promotion Other options mooted in the report include offering 'green visas' for jobs that contribute to achieving the government's target of hitting net zero by 2050, or reducing salary and skills thresholds right across the economy. Keir Starmer announced the immigration crackdown last month, claiming it marked the end of 'a squalid chapter for our politics, our economy and our country' in which the post-Brexit Conservative government had overseen soaring migration. Net migration hit a record level above 900,000 in the year to June 2023 before dropping sharply after a series of changes made by Rishi Sunak's government, including tightening the rules for visa applicants to bring in dependents. In the 2024 calendar year net migration was 431,000. Starmer said net migration would fall 'significantly' as a result of the changes he has announced. As well as potentially causing labour shortages in key sectors, economists have said lower net migration could prompt the independent Office for Budget Responsibility to downgrade its growth forecasts. The government has been approached for comment.