23andMe Goes Bankrupt Following Disastrous Data Breach

23andMe, a leading human genetics and biotechnology company, has announced that it has initiated voluntary Chapter 11 proceedings in the US Bankruptcy Court for the Eastern District of Missouri.

The company’s aim is to enable  a sale process and to maximise the value of its business and as a consequence, millions of people will find that their DNA data is put up for sale.

The Company intends to continue operating its business in the ordinary way throughout the sale process. There are no changes to the way the company stores, manages, or protects customer data and it monitored a surge in DNA testing a couple of years ago. If you've ever used the service this means that your data could be on the table for sale.

Founded in 2006, 23andMe has steadily amassed a database of millions of people’s fundamental genetic information under the promise of helping them understand their disposition to diseases and potentially connecting with relatives. In 2023 th company suffered a disastrous event when hackers gained access to the private data of 6.9 million users. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives and ancestry reports.

The subsequent mishandling of the breach by the company prompted a backlash from customers and investors, likely contributing to its financial failure. Now, the company’s bankruptcy filing means that customer  information is poised to be sold, causing serious concerns amongst privacy experts and advocates.

23andMe's privacy statement, which all customers must accept to use the service, contains provisions that it may sell your personal information if it is ever involved in bankruptcy proceedings. The California Department of Justice  Attorney General has issued an urgent customer alert, outlining some of the actions customers can take to protect their data before 23andMe sells it off to the highest bidder.

Customers can delete their account and personal information on 23andMe's website, specifically in the Settings section of their profile. Before you do, you can also download a copy of your data for your personal storage, before selecting "Delete Data" in the 23andMe Data section.

Customers who previously opted to have your saliva and DNA stored by 23andMe, can also change this preference and get it destroyed by the company in the Preferences section. They can also revoke permission for their genetic data to be used for research in the Research and Product Consents section of the account settings page.

By deleting your account this should ensure your personal data, genetic data included, gets deleted, however there are some problems.

23andMe has insisted that any new owner would have to comply with existing laws around the sale and use of consumer genetic data, but the reality in the US is that only a handful of states legally protect this type of personal information. These are primarily targeted at California consumers but everyone who has ever used 23andMe can access these settings and should be able to carry out at least some of the steps to protect their data.

The main thing you should do to protect your genetic privacy is to delete your account.

There is, however,  one problem, The company says it will have to retain some information in its archives even if you delete your account. “23andMe and/or our contracted genotyping laboratory will retain your Genetic Information, date of birth, and sex as required for compliance with applicable legal obligations … even if you chose to delete your account,” the company’s privacy policy reads.

23andMe   |   Techradar  |   Telegraph   |  California Attorney General   |   NBC   |   Guardian  

Image: Ideogram

You Might Also Read: 

23andMe Sparks A Rethink About Safeguarding Critical Data:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« MS Windows Zero Day Vulnerability Widely Exploited
British Science Minister Uses ChatGPT For Policy Advice »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

DCL Search & Select

DCL Search & Select

DCL Search & Selection connect candidates to the best companies in the IT Security, Telco, UC, Outsourcing, ERP, Audit & Control markets.

CW Jobs

CW Jobs

CWJobs.co.uk is a leading specialist IT recruitment website covering all areas of IT including Cyber Security.

NuData Security

NuData Security

NuData Security, A Mastercard Company, is an award winning behavioral biometrics company.

Picus Security

Picus Security

Huge gaps often exists between the "perceived"​ and "actual"​ IT security level of an organization. Picus Security continuously assesses security controls and reveals deficient ones before hackers do.

SAS Institute

SAS Institute

SAS is a leader in business analytics software and services providing solutions for a wide range of critical business areas including risk management, compliance and fraud prevention.

ACM-CCAS

ACM-CCAS

ACM is a UKAS-accredited certification body helping businesses around the world perform to a higher standard. Our certifications include ISO 27001 and ISO 22301.

NINJIO

NINJIO

NINJIO is a leader in cybersecurity awareness training. View IT Security Awareness through a different lens - entertain and educate your users through storytelling.

KnectIQ

KnectIQ

Building Trust Environments in a Zero-Trust World. KnectIQ offers KIQAssure, an Ultra High Security Solution for Data in Flight.

Evalian

Evalian

Evalian is a data protection services provider. Working with organisations of all sizes, we specialise in Data Protection, GDPR, ISO Certification & Information Security.

Apex Systems

Apex Systems

Apex Systems is a world-class technology services business that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions.

Plex IT

Plex IT

Plex IT provides managed IT services to organisations along with managed security services.

Imprivata

Imprivata

Imprivata is the digital identity company for life- and mission-critical industries, redefining how organizations solve complex workflow, security, and compliance challenges.

ActiveFence

ActiveFence

ActiveFence enables Trust & Safety teams to be proactive about online integrity so they can keep their users safe from online harm – across content formats, languages, and abuse areas.

CyFlare

CyFlare

CyFlare’s security platform integrates your tools with ours – delivering true positives, automated remediation, and interactive analytics built for security management teams.

Zenzero

Zenzero

Zenzero simplifies technology adoption and supports our customers through managed and outsourced IT support.

TR-CERT (USOM)

TR-CERT (USOM)

TR-CERT (Ulusal Siber Olaylara Müdahale Merkezi - USOM) is the national Computer Emergency Response Team of Turkey.