23andMe Goes Bankrupt Following Disastrous Data Breach

23andMe, a leading human genetics and biotechnology company, has announced that it has initiated voluntary Chapter 11 proceedings in the US Bankruptcy Court for the Eastern District of Missouri.

The company’s aim is to enable  a sale process and to maximise the value of its business and as a consequence, millions of people will find that their DNA data is put up for sale.

The Company intends to continue operating its business in the ordinary way throughout the sale process. There are no changes to the way the company stores, manages, or protects customer data and it monitored a surge in DNA testing a couple of years ago. If you've ever used the service this means that your data could be on the table for sale.

Founded in 2006, 23andMe has steadily amassed a database of millions of people’s fundamental genetic information under the promise of helping them understand their disposition to diseases and potentially connecting with relatives. In 2023 th company suffered a disastrous event when hackers gained access to the private data of 6.9 million users. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives and ancestry reports.

The subsequent mishandling of the breach by the company prompted a backlash from customers and investors, likely contributing to its financial failure. Now, the company’s bankruptcy filing means that customer  information is poised to be sold, causing serious concerns amongst privacy experts and advocates.

23andMe's privacy statement, which all customers must accept to use the service, contains provisions that it may sell your personal information if it is ever involved in bankruptcy proceedings. The California Department of Justice  Attorney General has issued an urgent customer alert, outlining some of the actions customers can take to protect their data before 23andMe sells it off to the highest bidder.

Customers can delete their account and personal information on 23andMe's website, specifically in the Settings section of their profile. Before you do, you can also download a copy of your data for your personal storage, before selecting "Delete Data" in the 23andMe Data section.

Customers who previously opted to have your saliva and DNA stored by 23andMe, can also change this preference and get it destroyed by the company in the Preferences section. They can also revoke permission for their genetic data to be used for research in the Research and Product Consents section of the account settings page.

By deleting your account this should ensure your personal data, genetic data included, gets deleted, however there are some problems.

23andMe has insisted that any new owner would have to comply with existing laws around the sale and use of consumer genetic data, but the reality in the US is that only a handful of states legally protect this type of personal information. These are primarily targeted at California consumers but everyone who has ever used 23andMe can access these settings and should be able to carry out at least some of the steps to protect their data.

The main thing you should do to protect your genetic privacy is to delete your account.

There is, however,  one problem, The company says it will have to retain some information in its archives even if you delete your account. “23andMe and/or our contracted genotyping laboratory will retain your Genetic Information, date of birth, and sex as required for compliance with applicable legal obligations … even if you chose to delete your account,” the company’s privacy policy reads.

23andMe   |   Techradar  |   Telegraph   |  California Attorney General   |   NBC   |   Guardian  

Image: Ideogram

You Might Also Read: 

23andMe Sparks A Rethink About Safeguarding Critical Data:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« MS Windows Zero Day Vulnerability Widely Exploited

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Arcitura Education

Arcitura Education

Arcitura is a leading global provider of progressive, vendor-neutral IT training and certification programs.

AppRiver

AppRiver

AppRiver is a global provider of cloud-based email and web security solutions that protect businesses worldwide from today's ever-changing online threats.

Digital Infrastructure Association (DINL)

Digital Infrastructure Association (DINL)

DINL is the leading representative for companies and organisations which are active within the Dutch digital infrastructure sector.

Cloudmark

Cloudmark

Cloudmark is a trusted leader in intelligent threat protection against known and future attacks, safeguarding 12 percent of the world’s inboxes from wide-scale and targeted email threats.

Dark Cubed

Dark Cubed

Dark Cubed is an easy-to-use cyber security software as a service (SaaS) platform that deploys instantly and delivers enterprise-grade threat identification and protection at a fraction of the cost.

1Password

1Password

1Password combines industry-leading security with award-winning design to bring private, secure, and user-friendly password management to everyone.

Feroot Security

Feroot Security

Feroot Security secures client-side web applications so that businesses can deliver a flawless user experience to their customers. Our products help organizations protect their client-side surface.

Cryptr

Cryptr

Cryptr provides plug and play authentication to manage all your authentication strategies in one place with just a few lines of code.

Anjuna Security

Anjuna Security

Software from Anjuna Security effortlessly enables enterprises to safely run even their most sensitive workloads in the public cloud.

aFFirmFirst

aFFirmFirst

aFFirmFirst is a unique software solution offering a simple yet effective way for businesses to protect and control their online images and logo, as well as allowing one-click website verification.

ViCyber

ViCyber

ViCyber is an Australian based company whose mission is to simplify and strengthen cybersecurity for all businesses, irrespective of size.

Silicon Valley Cybersecurity Institute (SVCSI)

Silicon Valley Cybersecurity Institute (SVCSI)

SVCSI aims to investigate, develop, and promote technical excellence and the best security practices for dependable and secure systems and applications.