Skip to content
Thursday 13 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,781.78
-0.47%
DAX
26,372.03
+0.16%
CAC 40
8,664.18
-0.12%
STOXX 50
6,557.65
+0.36%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Tuesday 17 June 2025 2:45 pm  |  Updated:  Tuesday 17 June 2025 10:23 am

23andMe handed huge fine days after rescue

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
23andMe has been fined more than £2m. (Photo by Justin Sullivan/Getty Images)
23andMe has been fined more than £2m. (Photo by Justin Sullivan/Getty Images)

Testing firm 23andMe has been fined more than £2m for failing to protect the sensitive personal and genetic data of more than 155,000 UK customers, in what regulators described as a “profoundly damaging” breach.

The UK’s Information Commissioner’s Officer (ICO) has fined the company £2.31m following a joint investigation with its Canadian counterpart, the Office of the Privacy Commissioner of Canada, in the wake of a large-scale cyber attack in 2023.

The breach exploited reused login credentials via a “credential stuffing” campaign, resulting in hackers accessing users’ names, ethnicity, genetic traits, health reports and family trees.

23andMe’s ‘delayed and inadequate’ response

The breach occurred between April and September 2023, during which hackers systematically accessed accounts using stolen login credentials from previous unrelated breaches.

Despite several warning signs – including a failed attempt to log into 1m accounts in a single day in July 2023 and activity involving profile transfers – the firm failed to launch a full investigation until October, when stolen data surfaced for sale on Reddit.

The ICO concluded that 23andme had violated UK protection law in three ways: by failing to require multi-factor authentication, lacking proper data control, and failing to detect and respond in a timely manner.

“23andMe failed to take basic steps to protect this information”, said UK information commissioner John Edwards.

“Once this information is out there, it cannot be changed or reissued like a password or credit card number”.

Canadian privacy commissioner Philippe Dufresne added that the breach underscored the need for stronger security in an era of increasing ransomware and data threats: “Organisations that hold sensitive data must act with vigilance – and speed”.

Bankruptcy, bid war and founder’s comeback

The ICO fine comes just days after 23andMe’s co-founder Anne Wojcicki won a bid to regain control of the company through a £305m bid via her nonprofit, TTAM Research Institute.

She outbid pharmaceutical giant Regeneron which had earlier agreed to acquire the firm for £256m in a bankruptcy auction.

Once valued at $6bn, 23andMe filed for Chapter 11 bankruptcy in March 2025 after a dramatic fall in demand and lasting damage from the breach.

Read more

London-listed healthcare services firm hit by cyberattack

Assura has been the subject of a ferocious bidding war for nearly six months

Wojcicki’s return marks a last-ditch attempt to revive the company’s mission, now under nonprofit ownership.

“I am thrilled that TTAM will be able to continue the mission of 23andMe to help people access, understand and benefit from the human genome”, said Wojcicki on Friday.

TTAM’s acquisition, which includes the company’s Personal Genome Service, Research Services, and Lemonaid Health, is pending court approval.

An industry wake-up call

The breach and subsequent enforcement action come at a time of growing scrutiny around data protection in biotech.

Nick Portch, director at Equinix, said secure collaboration and data sharing is essential for innovation, but must be underpinned by trust and infrastructure.

“Given the sensitivity of the data in life sciences, companies are right to be cautious – but secure sharing is possible”, Portch argued. “Sharing data opens the door to more impactful medical treatments and faster outcomes”.

The penalty also lands amid a broader UK push to back research and innovation.

As part of last week’s Spending Review, Chancellor Rachel Reeves confirmed that public R&D funding will rise to £22.6bn by 2029, supporting industrial stratey areas including AI, drug discovery and biotech manufacturing.

The ICO said 23andme has since improved its systems sufficiently to close the investigation.

Yet, the regulator warned other firms that failure to act on early signs of intrusion will not be tolerated.

“Data protection doesn’t stop at borders”, Edwards added. “And neither do we”.

Read more

Nottingham Forest owner Marinakis sues Crystal Palace for defamation

Evangelos Marinakis, owner of Nottingham Forest, in a dark jacket and white shirt, looking serious at a stadium.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • 23andme
  • cyber attack
  • cyber attacks
  • data breach
  • health
  • ICO
  • Information Commissioner's Office

Trending Articles

  • Five-star Mayfair hotel hit with HMRC winding-up petition

  • It’s not just Jason Arday, most of sociology is a scam

  • IT consultant ordered to pay £50,000 after being accused of stealing Soho House members’ personal details

  • Revolut takes flight with launch of new airport lounges

  • As it happened: FTSE 100 falls as Iran and US clash over Strait of Hormuz; Oil stockpiles ‘rapidly depleting’

More from Morning Wire

  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • Nottingham Forest owner Marinakis sues Crystal Palace for defamation

    Sport Business
    Evangelos Marinakis, owner of Nottingham Forest, in a dark jacket and white shirt, looking serious at a stadium.
  • Virgin Media slapped with £28m fine for stopping customers cancelling deals

    Telecoms
    Vans parked at a bustling city intersection surrounded by tall buildings and pedestrians, highlighting urban transportatio...
  • Tesco Mobile breaches £600m debt facility after reporting failure

    Telecoms
    Overhead view of a brightly lit Tesco store interior with shoppers, product aisles, and Clubcard Prices signage.
  • Thames Water faces fresh threat to survival after pensions regulation breach

    Water
    Thames Water infrastructure with pipes and maintenance workers, highlighting water management efforts in London
  • Chelsea fined £10m, avoid points penalty and receive Mykhailo Mudryk boost

    Sport Business
    A male Chelsea FC player, possibly Mykhailo Mudryk, in a blue and black long-sleeved training top, stretching.
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • Everton Friedkin Group owners inject £38m, reportedly to pay Burnley

    Sport Business
    Hill Dickinson Stadium exterior, Liverpool, with fans on steps, waterfront, and city skyline.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook