惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Hacker News
The Hacker News
Jina AI
Jina AI
aimingoo的专栏
aimingoo的专栏
博客园_首页
B
Blog RSS Feed
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
B
Blog
MyScale Blog
MyScale Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 热门话题
D
Docker
A
Arctic Wolf
G
Google Developers Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Google DeepMind News
Google DeepMind News
Cisco Talos Blog
Cisco Talos Blog
P
Privacy International News Feed
I
Intezer
博客园 - 叶小钗
T
Threat Research - Cisco Blogs
MongoDB | Blog
MongoDB | Blog
美团技术团队
C
CERT Recently Published Vulnerability Notes
Project Zero
Project Zero
S
Securelist
P
Proofpoint News Feed
Simon Willison's Weblog
Simon Willison's Weblog
V
Visual Studio Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
博客园 - 三生石上(FineUI控件)
Forbes - Security
Forbes - Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
The Cloudflare Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
V
Vulnerabilities – Threatpost
N
News and Events Feed by Topic
博客园 - Franky
The Last Watchdog
The Last Watchdog
T
Tailwind CSS Blog
T
Tenable Blog
Hacker News: Ask HN
Hacker News: Ask HN
雷峰网
雷峰网
Know Your Adversary
Know Your Adversary
Scott Helme
Scott Helme
S
SegmentFault 最新的问题
L
Lohrmann on Cybersecurity
F
Full Disclosure
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations UK's Cyber Security and Resilience Bill makes Parliamentary debut Cyber insurers paid out over twice as much for UK ransomware attacks last year Cyberpunks mess with Canada's water, energy, and farm systems Trump's workforce cuts blamed as America's cyber edge dulls Feds flag active exploitation of patched Windows SMB vuln How malware vaccines could stop ransomware's rampage Salesforce refuses to pay ransomware crims' extortion demand Germany slams brakes on EU's Chat Control snoopfest Germany slams brakes on EU's Chat Control snoopfest Employees regularly paste company secrets into ChatGPT Oracle tells Clop-targeted EBS users to apply July patch Red Hat repos raided, claims cybercrew, files stolen Suspected Chinese spies broke into 'numerous' enterprises UK gov acknowledges 'strong case' for JLR financial support JLR extends shutdown – again – as toll on workers laid bare UK chancellor blames cyberattacks on Russia despite evidence Fortra discloses 10/10 severity bug in GoAnywhere MFT Entra ID bug could have granted access to every tenant UEFI Secure Boot for Linux Arm64 – where do we stand? JLR says cyber cleanup to take additional week Insider blamed for FinWise data breach affecting nearly 700K Nork snoops whip up fake military ID with help from ChatGPT UK government dragged for incomplete security reforms Church of England abuse victims exposed by lawyer's email US spy chief claims UK backdown on Apple backdoor demand Workday confirms CRM breach via social engineering Black Hat/DEF CON: AI more useful for defense than hacking Ex-White House cyber guru talks Microsoft security fails CISA releases malware analysis for Sharepoint Server attack China: US spies used Microsoft Exchange 0-day to steal info Security pros drowning in threat-intel data Identity attacks surge 156% as phishermen get craftier Organizations can’t keep up with supply chain security musts Amazon CISO: Iranian hacking crews ‘on high alert’ Employers are demanding too much from junior cyber recruits FCA warned four staffers who pocketed regulator data Ransomware just wrecked your network – now what? Ivanti RCE attacks 'ongoing,' exploitation hits clouds Ex-NSA listened to Scattered Spider's calls: 'They're good' Snowflake CISO talks lessons learned from breaches, improv Why CVSS is failing us and what we can do about it Infosec pros still aren't nailing the basics of AI security Ransomware crims targeting systems between IT and operations Why aggregating asset inventory leads to better security NCSC and industry at odds over how to tackle shoddy software Powerschool extortionists may not have deleted stolen data CrowdStrike trims workforce by 5 percent, aims to rely on AI NSO Group must pay Meta $168M in WhatsApp spy case Ghost in the shell script: Boffins seek code correctness How Intruder finds what others miss in cloud security Linux malware can avoid syscall-based endpoint protection Infosec pro blabs about alleged malware mishap on LinkedIn The future of AI in cybersecurity in a word – optimistic CVE board 'kept in the dark' on funding, members say Security snafus caused by third parties up from 15% to 30% Blue Shield shared 4.7M people's health info with Google Ads Who needs phishing when your login's already in the wild? US cyber defenses are being dismantled from the inside Bug hunter obtains an SSL cert for Alibaba Cloud in 5 steps
UK data watchdog fines 23andMe £2.3M over 2023 breach
Connor Jones Connor Jones · 2025-06-17 · via The Register - Security: CSO

CSO

23andMe hit with £2.3M fine after exposing genetic data of millions

Penalty follows year-long probe into flaws that allowed attack to affect so many

The UK's data watchdog is fining beleaguered DNA testing outfit 23andMe £2.31 million ($3.13 million) over its 2023 mega breach.

Among the various security failings demonstrated by the genetics company were:

  • Unsatisfactory authentication measures, including lack of mandatory MFA and unsecure password requirements
  • No measures taken to prevent accessing and downloading raw genetic data
  • No measures to adequately monitor, detect, or respond to security threats to user data

The announcement comes a year after the Information Commissioner's Office (ICO) and Office of the Privacy Commissioner of Canada (OPC) teamed up to investigate 23andMe and the failures that led to attackers compromising nearly 7 million users' data.

John Edwards, the UK's Information Commissioner, said: "This was a profoundly damaging breach that exposed sensitive personal information, family histories, and even health conditions of thousands of people in the UK. As one of those impacted told us, once this information is out there, it cannot be changed or reissued like a password or credit card number.

"23andMe failed to take basic steps to protect this information. Their security systems were inadequate, the warning signs were there, and the company was slow to respond. This left people's most sensitive data vulnerable to exploitation and harm."

The ICO went on to note the five-month gap between the attacker's credential-stuffing activity, which began in April 2023, and 23andMe finally acknowledging the attack publicly in October that year.

It said 23andMe "missed many opportunities to act" during this time and only did so after the stolen data was put up for sale on Reddit.

23andMe took until the end of 2024 to demonstrate that it had sufficiently addressed the fundamental issues that underpinned the credential-stuffing attack, the ICO's announcement stated.

The genetics company's fine represents a significant reduction compared to the sum the ICO was previously considering when it issued its Notice of Intent to fine 23andMe in March.

At the time, the proposed fine was £4.59 million ($6.22 million). An ICO spokesperson told The Register today: "By law, the company was given the opportunity to send representations regarding our findings of fact, the application of the law, the proposed form of regulatory action, if any, and the quantum of the proposed fine. 

"We considered these representations and made our final decision to issue a £2.31 million fine to 23andMe for breaching data protection law."

Attack facts

The 23andMe breach took place between April and September 2023, during which time the attackers used credential-stuffing techniques to access a small portion of the total user accounts.

Around 14,000 accounts were accessed during this time, representing approximately 0.1 percent of the total registrants on the platform. 

However, the total number of affected users was much higher. This is in large part due to so many users opting into 23andMe's DNA Relatives feature, one of the main selling points of the service, which allowed users to connect with their suspected relatives around the world.

The feature essentially opened up data sharing between 23andMe users at a massive scale, meaning the compromise of just 14,000 accounts led to the personal data of around 6.9 million people being stolen.

According to the ICO, 155,592 UK residents were affected. They potentially had data points such as names, birth years, self-reported city or postcode-level location, profile images, race, ethnicity, family trees, and health reports accessed, although this differed on a per-user basis.

Chapter 11

23andMe filed for Chapter 11 bankruptcy protection earlier this year, raising the question of how exactly it will pay the ICO's fine.

The data watchdog is aware of the proceedings, which involve an auction process, and that a sale hearing is scheduled for today, where founder Anne Wojcicki is expected to be formally declared the owner following a reported $305 million bid via her nonprofit TTAM Research Institute.

The ICO is in close contact with 23andMe's lawyers and the US trustee, and assures that 23andMe is still obligated to comply with the UK GDPR and the regulator's enforcement actions.

It deems its fine-collection policy to be robust but fair, offering payment plans for organizations that are enduring genuine financial hardship, a criterion that 23andMe may meet, although the regulator did not comment on this.

Organizations that can pay but won't can expect the ICO to pursue formal recovery actions that could lead to insolvency.

Philippe Dufresne, Privacy Commissioner of Canada, said: "Strong data protection must be a priority for organizations, especially those that are holding sensitive personal information. With data breaches growing in severity and complexity, and ransomware and malware attacks rising sharply, any organization that is not taking steps to prioritize data protection and address these threats is increasingly vulnerable.

"Joint investigations like this one demonstrate how regulatory collaboration can more effectively address issues of global significance. By leveraging our combined powers, resources, and expertise, we are able to maximize our impact and better protect and promote the fundamental right to privacy of individuals across jurisdictions."

The Register asked 23andMe to comment. A spokesperson said that by the end of 2024, 23andMe had taken steps to improve account security. TTAM, its buyer, committed to stronger privacy protections – including opt-outs, breach notifications, a privacy board, identity monitoring, and limits on future data sales – even pledging not to sell genetic data in bankruptcy without following its privacy rules. ®