23andMe Goes Bankrupt Following Disastrous Data Breach

23andMe, a leading human genetics and biotechnology company, has announced that it has initiated voluntary Chapter 11 proceedings in the US Bankruptcy Court for the Eastern District of Missouri.

The company’s aim is to enable  a sale process and to maximise the value of its business and as a consequence, millions of people will find that their DNA data is put up for sale.

The Company intends to continue operating its business in the ordinary way throughout the sale process. There are no changes to the way the company stores, manages, or protects customer data and it monitored a surge in DNA testing a couple of years ago. If you've ever used the service this means that your data could be on the table for sale.

Founded in 2006, 23andMe has steadily amassed a database of millions of people’s fundamental genetic information under the promise of helping them understand their disposition to diseases and potentially connecting with relatives. In 2023 th company suffered a disastrous event when hackers gained access to the private data of 6.9 million users. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives and ancestry reports.

The subsequent mishandling of the breach by the company prompted a backlash from customers and investors, likely contributing to its financial failure. Now, the company’s bankruptcy filing means that customer  information is poised to be sold, causing serious concerns amongst privacy experts and advocates.

23andMe's privacy statement, which all customers must accept to use the service, contains provisions that it may sell your personal information if it is ever involved in bankruptcy proceedings. The California Department of Justice  Attorney General has issued an urgent customer alert, outlining some of the actions customers can take to protect their data before 23andMe sells it off to the highest bidder.

Customers can delete their account and personal information on 23andMe's website, specifically in the Settings section of their profile. Before you do, you can also download a copy of your data for your personal storage, before selecting "Delete Data" in the 23andMe Data section.

Customers who previously opted to have your saliva and DNA stored by 23andMe, can also change this preference and get it destroyed by the company in the Preferences section. They can also revoke permission for their genetic data to be used for research in the Research and Product Consents section of the account settings page.

By deleting your account this should ensure your personal data, genetic data included, gets deleted, however there are some problems.

23andMe has insisted that any new owner would have to comply with existing laws around the sale and use of consumer genetic data, but the reality in the US is that only a handful of states legally protect this type of personal information. These are primarily targeted at California consumers but everyone who has ever used 23andMe can access these settings and should be able to carry out at least some of the steps to protect their data.

The main thing you should do to protect your genetic privacy is to delete your account.

There is, however,  one problem, The company says it will have to retain some information in its archives even if you delete your account. “23andMe and/or our contracted genotyping laboratory will retain your Genetic Information, date of birth, and sex as required for compliance with applicable legal obligations … even if you chose to delete your account,” the company’s privacy policy reads.

23andMe   |   Techradar  |   Telegraph   |  California Attorney General   |   NBC   |   Guardian  

Image: Ideogram

You Might Also Read: 

23andMe Sparks A Rethink About Safeguarding Critical Data:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« MS Windows Zero Day Vulnerability Widely Exploited
British Science Minister Uses ChatGPT For Policy Advice »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

DMH Stallard

DMH Stallard

DMH Stallard is a mid-market law firm. Areas of expertise include cyber security and cyber crime.

DataLocker

DataLocker

DataLocker offers both hardware based external storage and software based cloud storage encryption solutions.

Tymlez Software & Consulting

Tymlez Software & Consulting

Tymlez Software and Consulting is a start-up specialised in blockchain technology for enterprises.

Cyber Future Foundation (CFF)

Cyber Future Foundation (CFF)

CFF was established to create a cyberspace where digital commerce and innovation can thrive based on trust and respect to individual privacy.

Sysorex Government Services

Sysorex Government Services

Sysorex Government Services helps customers meet their strategic missions by providing secure, optimized IT solutions that allow them to perform more efficiently and effectively.

Arab Information & Communication Technologies Organization (AICTO)

Arab Information & Communication Technologies Organization (AICTO)

The Arab ICT Organization (AICTO) is an Arab governmental organization working under the aegis of the league of Arab States.

Founder Shield

Founder Shield

Founder Shield is a data driven insurance brokerage focused excusively on rapidly evolving high-growth companies.

Global Cyber Risk (GCR)

Global Cyber Risk (GCR)

Global Cyber Risk is a technology and advisory services firm that provides first tier cybersecurity services to both large corporations and small and mid-sized businesses.

Adaptive Shield

Adaptive Shield

Addaptive Shield - Complete Control For Your SaaS Security. Proactively find and fix weaknesses across your SaaS platforms.

Neosecure

Neosecure

NeoSecure is a specialist Cybersecurity Solutions and Managed Services provider in Latin America.

Quantum Armor

Quantum Armor

Quantum Armor is a next-gen cyber security monitoring platform that allows you to continuously stay aware of your security posture, and proactively spot trends, vulnerabilities and potential attacks.

IPKeys Technologies

IPKeys Technologies

IPKeys delivers innovative cybersecurity and technology solutions focused on helping the federal government reduce risk and protect the US from cyberattacks.

CloudCover

CloudCover

CloudCover is a software-defined cybersecurity risk solution that provides risk awareness, risk analytics, and data security in real time.

Dope Security

Dope Security

Dope Security is a fly-direct Secure Web Gateway that eliminates the data center stopover architecture required by legacy providers, instead performing security directly on the endpoint.

Resilience Cyber insurance

Resilience Cyber insurance

Resilience helps to improve cyber resilience by connecting cyber insurance coverage with advanced cybersecurity visibility and a shared plan to reinforce great cyber hygiene.

Imprivata

Imprivata

Imprivata is the digital identity company for life- and mission-critical industries, redefining how organizations solve complex workflow, security, and compliance challenges.