logo
DNA testing firm 23andMe fined £2.3m by UK regulator for 2023 data hack

DNA testing firm 23andMe fined £2.3m by UK regulator for 2023 data hack

The Guardian4 hours ago

The genetic testing company 23andMe has been fined more than £2.3m for failing to protect the personal information of more than 150,000 UK residents after a large-scale cyberattack in 2023.
Family trees, health reports, names and postcodes were among the sensitive data hacked from the California-based company. It only confirmed the breach months after the infiltration started and once an employee saw the stolen data advertised for sale on the social media platform Reddit, according to the UK Information Commissioner's Office – which levied the fine.
The information commissioner, John Edwards, called the months-long incident across the summer of 2023 a 'profoundly damaging breach'. The compromise of UK data was just a fraction of the wider losses, with the data of 7 million people affected.
23andMe charges users £89 to have their DNA screened using a saliva-based kit, allowing them to discover where their distant ancestors came from in terms of their ethnicity and location. But many customers asked for their DNA data to be deleted from the company's archives after the hack and it filed for bankruptcy protection in the US in March.
The fine came as a $305m bid to buy the company led by its former chief executive, Anne Wojcicki, looked poised to retake control of the company in a bankruptcy auction.
Edwards said the data breach 'exposed sensitive personal information, family histories and even health conditions of thousands of people in the UK'.
'As one of those impacted told us: once this information is out there, it cannot be changed or reissued like a password or credit card number,' he said.
23andMe failed to take basic steps to protect the information and their security systems were inadequate, the UK data protection regulator found. The breaches included failing to install tougher user authentication.
The hacker exploited a common weakness caused by users reusing passwords that had already been stolen in other unrelated data breaches. Hackers then used automated tools to try these passwords in a tactic called 'credential stuffing'.
'The warning signs were there, and the company was slow to respond,' said Edwards, who carried out the investigation jointly with the privacy commissioner of Canada. 'This left people's most sensitive data vulnerable to exploitation and harm.'
Sign up to First Edition
Our morning email breaks down the key stories of the day, telling you what's happening and why it matters
after newsletter promotion
A spokesperson for the company said 23andMe had since implemented multiple steps to increase security to protect individual accounts and information. They said that as part of the deal to acquire 23andMe, Wojcicki's non-profit, the TTAM Research Institute, has made 'binding commitments to enhance protections for customer data and privacy, including allowing individuals to delete their account and opt out of research at any time' and 'agreeing not to sell or transfer genetic data under a subsequent bankruptcy or change of control', and offering customers two years of free identity theft monitoring.
The fine is among several multimillion pound punishments meted out by the ICO in recent years for failure to protect data from hacks and ransomware attacks. In 2022, it fined the construction company Interserve £4.4m when staff data was compromised, including contact details, bank accounts, sexual orientation and health.
In March this year it fined an NHS IT supplier, Advanced Computer Software Group, nearly £3.1m for security failings that put the personal information of nearly 80,000 people at risk.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Bosses of Octopus Energy and SSE clash over 'postcode pricing' proposals
Bosses of Octopus Energy and SSE clash over 'postcode pricing' proposals

Sky News

time11 minutes ago

  • Sky News

Bosses of Octopus Energy and SSE clash over 'postcode pricing' proposals

The head of Britain's biggest energy supplier has claimed his competitors oppose proposals for so-called postcode pricing because they financially benefit from the current system. Octopus Energy chief executive Greg Jackson told Sky News his business's rivals were against customers being charged based on where they lived, rather than on a national basis, because they would lose out on profits. He said: "A very small number of companies that today get paid tens of millions, sometimes in a single day, to turn off wind farms and generate gas elsewhere, don't like it. "The reason you're seeing that kind of behaviour from the rivals is they are benefiting from the current system that's generating incredible profitability." The government is currently considering whether to introduce the policy, which is also known as zonal pricing. Energy secretary Ed Miliband is expected to make a decision on the proposals by this summer. Octopus has become Britain's biggest supplier with more than seven million customers. Mr Jackson has been a vocal proponent, as he said he wants to charge customers less and boost government electrification policies by having cheaper electricity costs. What is postcode pricing? Zonal pricing would mean electricity bills are based on what region you live in. Some parts of Britain, like northern Scotland, are home to huge energy producers in the form of offshore wind farms. But rather than feeding electricity to local homes and businesses, power goes into a nationwide auction and is bought to go across Britain. As the energy grid is still wired for the old coal-producing sites rather than the modern renewable generators, it's not straightforward to get electricity from where it's increasingly produced to the places people live and work. That leads to traffic jams on the grid, blocking paid-for electricity moving to where it's needed and a system where producers can be paid a second time, to power down, and other suppliers, often gas plants, are paid to meet the shortfall. Zonal pricing is designed to prevent paying the generators for power that can't be used. It would mean those in Scotland have lower wholesale energy costs while those in the south, where there is less renewable energy production, would have higher wholesale costs. Whether bills go up or down depends on implementation. Savings from one region could be spread across Britain, lowering bills across the board. Mr Miliband has said he's not going to decide to raise prices. However, SSE's chief executive Alistair Phillips-Davies described the policy as a "distraction" and said it could affect already agreed-upon upgrades of the national grid that will lower costs. "I think you've got a very, very small number of people who are asking for this. It's just a distraction. We should remove it now," he said. While Octopus Energy estimates that said postcode pricing could be introduced in two to four years, Mr Phillips-Davies said it could take until 2032 before it was implemented, by which time Britain would have "built much of the networks that are required to get the energy from these places down into the homes and businesses that actually need it". "We just need to stay true to the course," he added. Unions, as well as industry and energy representatives, have also spoken out against the policy. Opponents include eco-tycoon Dale Vince and trade body UK Steel. A joint letter signed by SSE, UK Steel, Ceramics UK and British Glass, along with the unions GMB, Unite and Unison, said zonal pricing could lead to scaled-back investment due to uncertainty and higher bills. A separate letter signed by 55 investors, including Centrica and the Ontario Teachers' Pension Plan, has also criticised the policy. 1:21 However, Mr Jackson said many investors had not voiced opposition, with thousands of small and medium businesses instead backing the policy in the hope of paying less on energy bills.

Terrifying moment driver catapults holidaymakers into air after deliberately smashing into them in row over double booked AirBnB rental - as he is jailed
Terrifying moment driver catapults holidaymakers into air after deliberately smashing into them in row over double booked AirBnB rental - as he is jailed

Daily Mail​

time12 minutes ago

  • Daily Mail​

Terrifying moment driver catapults holidaymakers into air after deliberately smashing into them in row over double booked AirBnB rental - as he is jailed

This is the terrifying moment a driver deliberately smashed into two holidaymakers, catapulting them into the air, in a row over a double booked AirBnB rental. Johnathan Newbury, 33, was yesterday jailed for ten years for ploughing his SUV into pedestrians Ryan Jones, 18, and a 17-year-old boy. He had armed himself with a zombie knife and was 'intent on violence' during the car attack in July last year, a court heard. The row broke out after Newbury discovered the AirBnB he had rented for the weekend in Cardiff, Wales, had accidently been double booked. Newbury and his friend Elliott Fiteni, 23, were already inside the property when Mr Jones and the teenager turned up for their own stay. Merthyr Tydfil Crown Court heard Newbury began hurling threats at the pair, shouting 'I'll f*** you up' through a window. He then hunted the men in a black SUV before mowing them down in the street. Prosecutor James Wilson said footage showed the vehicle 'immediately speeding up' and striking two of them as they crossed. Newbury then fled the scene as the victims were left on the ground with serious injuries. Mr Jones suffered injuries to his pelvis and right foot while the teenager lost consciousness and sustained injuries to his jaw, ribs, chest and abdomen. Mr Wilson said the row had started over the booking made in the Cathays area of Cardiff in July of last year where Newbury was due to stay with friend Elliot Fiteni. He said: 'Mr Jones, [...] and another friend had booked an Airbnb on Bruce Street called the Comfortable Stay. 'By chance, a booking had been made at the same address on behalf of Mr Fiteni, who accepted he stayed at the address along with Mr Newbury. 'They were already at the building when Mr Jones and [...] walked towards it.' Newbury, of Cardiff, was found guilty of causing grievous bodily harm with intent, attempting to inflict grievous bodily harm and possession of a bladed article. Judge Jeremy Jenkins Newbury 'You were present at an AirBnB at Bruce Street in Cardiff, the two complainants [...] and Mr Jones had also booked accommodation at the same address and there had been an earlier altercation.' The judge said Newbury had then been part of a group 'armed with what has been described as a zombie knife' and 'intent on violence'. He said: 'The clear aim was to attack [...] and Mr Jones, both ran away from the scene.' Judge Jenkins said Newbury was the driver of the SUV which was 'seen to speed up, to drive on the wrong side of the road into the junction and to deliberately collide with the two men, throwing them up in the air.' Newbury was handed an extended sentence of 10 years and told he must serve at least five years and four months behind bars.

Tighter immigration rules could hit UK net zero mission, report warns
Tighter immigration rules could hit UK net zero mission, report warns

The Guardian

time16 minutes ago

  • The Guardian

Tighter immigration rules could hit UK net zero mission, report warns

Tough rules announced in the government's immigration white paper could jeopardise the UK's net zero mission by causing labour shortages, a report has warned. Labour's white paper released last month included plans to raise the minimum qualification for skilled worker visas from A-level equivalent to degree and to maintain the higher salary threshold of £38,700 introduced by the outgoing Conservative government last year. A report by the Centre for European Reform (CER), calculates that more than half of the foreign-born workers doing 'green jobs' in the UK – 260,000 out of 465,000 – would not have been allowed in under the new rules. Ministers are relying on employers to raise wages and provide more training in order to attract domestic workers into these roles, but John Springford, an associate fellow at the CER, said that could push up the costs to consumers of going green. 'If labour shortages raise the cost of decarbonising buildings, fewer people will insulate their homes or buy heat pumps,' he said. Using Office for National Statistics data, the CER defined a green job as one in which more than a third of the worker's time is spent on green tasks. Many of these are in the construction sector, given the need to retrofit homes with low-carbon technologies, for example. The report also suggests construction jobs more generally may be difficult to fill under the new visa regime, casting doubt on the government's target to build 1.5m homes by the end of the parliament. 'Construction is labour-intensive and has a lot of employee turnover, because the work is physical and seasonal. Given that the government's aim is to expand housebuilding and decarbonise buildings concurrently, the sector is most at risk of labour shortages as a result of the government's immigration proposals,' the report says. Labour has announced that the existing 'immigration salary list', which allows people doing specific types of job to be brought in on lower pay, will be replaced with a similar 'temporary shortage list'. To avoid this becoming a long-term measure, the relevant industry will be expected to set out plans to train and recruit more UK workers. The CER said that using a shortage list as a safety valve could be problematic because the higher salary threshold elsewhere means migrants in the sectors with shortages are unlikely to be able to shift into other jobs, leaving them vulnerable to exploitation by the employer who sponsors their visa. This problem arose in social care where holders of health and care visas were subject to exploitation by bad employers, with little chance of moving to another post. 'The government should keep an eye on labour shortages in occupations that are crucial for its net zero and housebuilding missions, and relax visa rules if needed,' Springford said. 'But offering exemptions to the rules for specific occupations is risky.' Sign up to Business Today Get set for the working day – we'll point you to all the business news and analysis you need every morning after newsletter promotion Other options mooted in the report include offering 'green visas' for jobs that contribute to achieving the government's target of hitting net zero by 2050, or reducing salary and skills thresholds right across the economy. Keir Starmer announced the immigration crackdown last month, claiming it marked the end of 'a squalid chapter for our politics, our economy and our country' in which the post-Brexit Conservative government had overseen soaring migration. Net migration hit a record level above 900,000 in the year to June 2023 before dropping sharply after a series of changes made by Rishi Sunak's government, including tightening the rules for visa applicants to bring in dependents. In the 2024 calendar year net migration was 431,000. Starmer said net migration would fall 'significantly' as a result of the changes he has announced. As well as potentially causing labour shortages in key sectors, economists have said lower net migration could prompt the independent Office for Budget Responsibility to downgrade its growth forecasts. The government has been approached for comment.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store