Lessons From the 23andMe Data Breach: Data Privacy in an Interconnected World

Martin Bastius
18.12.2023
999
min.

In a world shaped by information, the recent 23andMe data breach exposed the weaknesses in our interconnected data landscape. This breach not only revealed the sensitive genetic information of countless people but also underscored the far-reaching consequences of interconnected data in our digital age.

The 23andMe Data Breach

The incident that shook the world of genomics was not a direct attack on the company's servers; rather, it targeted individual user accounts. Accounts with reused or weak passwords were compromised in particular, giving hackers access to a goldmine of genetic data. Interestingly, the incident exploited a feature within 23andMe called "DNA Relatives," which allowed information to be extracted from a broad range of people who had used the service. Within a week, this incident led to four class-action lawsuits against 23andMe, all focused on the compromise of users' personal and health-related data.

The Interconnected Nature of Personal Data and the Rise of Privacy Concerns

This incident prompts us to reassess our notions of data protection, data security, and corporate responsibility in the information-driven economy. Genetic databases have a unique characteristic: when a person shares their DNA data with a company like 23andMe, it reveals not only information about themselves but also about their relatives, even if those relatives never provided their own DNA samples or consented to the data collection. In essence, their data becomes linked.

The consequences of neglecting how personal data affects others extend far beyond genetic data and reach into the broader information economy. The interconnected nature of data is no accident; it lies at the core of how companies operate in the information economy, but it also creates fairness issues. Every decision a person makes about their data has an impact on others, which can lead to consequences such as the following:

Identification and Tracking: 

Data can be used to identify and track individuals, even if they never provided their data directly. Combining data from various sources, such as social media, purchase history, and location data, can result in comprehensive profiling.

Discrimination: 

The stolen genetic information from the 23andMe data leak, including lists of people with specific ancestries, raises concerns about discrimination and harassment, since the leaked data includes names and locations. In addition, data on genetic predispositions such as type 2 diabetes, Parkinson's disease, or dementia can also be exploited, potentially leading to higher insurance premiums and employment discrimination.

Targeted Advertising and Manipulation: 

The interconnection of data enables the creation of highly detailed psychological profiles, which in turn enable personalized advertising and other forms of manipulation.

Security Risks: 

With interconnected data, the likelihood of data leaks and theft increases, since hackers only need to compromise one system to access a significant amount of data. These risks underscore the critical importance of robust data security measures and protecting individuals' information in our increasingly interconnected digital landscape.

Like 23andMe, companies such as AncestryDNA, MyHeritage, LivingDNA, and FamilyTreeDNA also collect and use interconnected personal data. This means these companies gather genetic data from their users and use it for various services, such as ancestry research, health risk assessment, and personal genetic counseling. 23andMe is not the first company to experience a data breach; other companies that have experienced breaches include:

  • Veritas Genetics, a DNA testing startup, experienced a data breach in its customer-facing portal that led to unauthorized access to some customer data. The company did not disclose when the breach occurred or details about the stolen data, but stated that only a few customers were affected and denied that any data was stolen. Although the breach did not compromise personal health information, it raises concerns about the security of genetic testing companies, particularly amid growing privacy concerns in the industry as law enforcement agencies gain access to DNA databases for criminal investigations.

 

  • Vitagene, a genetic testing company, discovered that one of its AWS databases had exposed consumer data, including full names, dates of birth, genetic health information, and other medical conditions of its users. The breach affected around 300 files containing raw genetic DNA data, some of which included users' names, as well as 1,401 user files stored in a less secure setting typically reserved for employee access. Although the database also contained some user contact details, such as e-mail addresses, no credit card information, passwords, or financial data were compromised in the incident.

Protect Your Privacy When Using DNA Testing Services

When sharing sensitive personal data such as health information, it's crucial to prioritize protecting your privacy, given the sensitive nature of genetic information and the potential risks associated with its disclosure. Here are some actionable steps:

Read privacy policies carefully: Before using a DNA testing service, thoroughly review its privacy policy and terms of use. Make sure you understand how your genetic data is collected, stored, and shared.

Enable two-factor authentication (2FA): To protect your DNA testing account, enable two-factor authentication (2FA) and use a strong password. 2FA adds an extra layer of security by requiring you to enter a code sent to your phone in addition to your password when you log in.

Use a strong passphrase: Use a passphrase instead of a single word. Passphrases are longer and more secure. Use the first letters, numbers, and punctuation marks of a memorable phrase to create a seemingly random combination of characters — you can also replace letters with numbers or symbols for added complexity.

Review your sharing options: DNA testing services often allow you to share genetic data with relatives or other users. Carefully review and adjust these options to control who can access your data.

Opt out of data sharing: Some services may use your data for research purposes or share it with third parties. Check whether there's an option to opt out of such data sharing or participation in research studies.

Regularly update your privacy settings: Regularly check the privacy settings on your DNA testing platform to make sure your data is protected according to your preferences.

Be cautious with third-party apps: Some DNA testing services offer third-party apps or tools to interpret your genetic data. Be cautious when accessing these apps and review their privacy policies.

Practice data minimization: Share only necessary information when using DNA testing services. Minimize the data you provide to the essential details required for the testing purpose. Avoid sharing excessive or unnecessary personal information.

Regularly review and delete data: Regularly review and manage your stored genetic data. Delete any information that's no longer needed or relevant. Many services allow users to delete their data; use this feature if you no longer need the stored information.

Stay informed: Keep learning about the latest privacy concerns, data retention policies, and potential risks related to genetic testing. Understanding this evolving landscape can help you make more informed decisions. Keep an eye on news about data leaks or security incidents at DNA testing companies. In the event of a leak, take appropriate steps to protect your accounts and data.

Final Thoughts:

In an era where our most personal information is increasingly interconnected, proactively protecting our privacy is essential. The 23andMe data breach serves as a stark reminder of the complex web of data sharing and the potential risks involved. By following these guidelines and staying informed, you can take control of your genetic data and minimize the risks of its exposure.

 

"Ensuring the protection of your data is not just a personal responsibility; it's a shared commitment to a safer, more secure digital world." 

Milos Djurdjevic, 
CEO at heyData
__wf_reserved_decorative
Published
18.12.2023
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories