23andMe Fined £2.31 Million by UK Over Genetic Data Leak

June 17, 2025, 1:45 PM UTC

23andMe was fined £2.31 million ($3.1 million) by UK regulators after a 2023 cyber attack exposed users’ genetic data in yet another privacy crisis surrounding the troubled DNA data bank.

The UK Information Commissioner’s Office announced the penalty Tuesday after a joint investigation with its Canadian counterpart. The former Silicon Valley startup violated UK data-protection laws, it said, by failing to put in place: appropriate authentication measures for customer login, relevant security steps for accessing raw genetic data and measures to detect and respond to cyber threats.

The shortcomings allowed a hacker to access the personal information of more than ...

Learn more about Bloomberg Law or Log In to keep reading:

Learn About Bloomberg Law

AI-powered legal analytics, workflow tools and premium legal & business news.

Already a subscriber?

Log in to keep reading or access research tools.