DNA testing: What happens if your genetic data is hacked?

The personal information of millions of people who sent swabs of their DNA to consumer testing services have been leaked in high profile hacks in recent years, leading to questions about how secure that genetic data is.
In autumn 2023, a hacker called Golem posted on a well-known message board for cybercriminals, announcing a trove of data stolen from 23andMe, one of the biggest names in at-home DNA testing.
News began to circulate suggesting the data breach on Friday 6 October 2023 may have even had antisemitic motivations.
23andMe co-founder Anne Wojcicki was among those whose profiles were allegedly included in the data breach.
Data breaches happen all the time, says Brett Callow, a threat analyst with cybersecurity firm Emsisoft.
A data breach that included ethnicity estimates given in ancestry reports could mean that Jewish people who had taken a DNA test could potentially have a permanent digital yellow star next to their names, photographs and geographical location.
With the data of half 23andMe's customers now in the hands of cybercriminals, the breach clearly affected far more than just Ashkenazi Jewish account holders.
In subsequent posts on the hackers forum, Golem supposedly offered the data of British, German and Chinese 23andMe users, as well as that of 23andMe chief executive Anne Wojcicki, her ex-husband and Google founder Sergey Brin, Elon Musk and members of the British Royal Family.
When news of the 23andMe data breach first broke, the reaction was relatively muted: the attention of Jewish groups was focused on the attacks Hamas had launched on Israel that weekend, and the rise in antisemitic hate incidents in the weeks that followed it.
Once those accounts had been infiltrated, the hacker was able to amass a much larger trove of data through the DNA Relatives feature of 23andMe, which allows account holders to connect with genetic relations.
In response to inquiries from journalists at TechCrunch in December 2023, 23andMe admitted that in fact the data of 6.9 million users - roughly one out every two people who had sent their DNA to the company - had been breached.
Prior to October 2023 this wasn't a necessary requirement to access an account on 23andMe, even though it held genetic ancestry data coupled with geographical and biographical information.
The October 2023 23andMe breach was the first time hackers had offered the data for sale.
Last year, America's Federal Trade Commission took action against two direct-to-consumer DNA testing companies, CRI Genetics and 1Health/Vitagene, for failing to keep DNA data secure.
Regardless of the motivation, any breach involving genetic data has potentially wide-ranging consequences.
In an age where an increasing number of financial decisions are made by algorithms that scrape all possible sources of information about an individual, there is a serious possibility of financial loss and discrimination arising from a leak of genetic data.
It's easy to imagine a scenario where leaked genetic data might lead to higher premiums or customers being denied cover entirely because of their genes, or being rejected for a long-term bank loan or mortgage because leaked data suggests a higher likelihood of the lender developing Alzheimer's and passing away before it could be was repaid in full.
23andMe has said the data breach of its user profiles did not include the leaking of raw DNA profiles, but the hacker still had access to ancestry reports that gave ethnicity estimates, geographical location, links to family trees and other personal information.
23andMe now faces several class action lawsuits in the US as a consequence of the data breach.
Even if it were possible to keep data as sensitive as our genetic code safe from hackers, there is no guarantee that once we have consented to share it with a corporation it will remain in their possession.


This Cyber News was published on packetstormsecurity.com. Publication date: Tue, 13 Feb 2024 22:43:04 +0000


Cyber News related to DNA testing: What happens if your genetic data is hacked?

How to perform a proof of concept for automated discovery using Amazon Macie | AWS Security Blog - After reviewing the managed data identifiers provided by Macie and creating the custom data identifiers needed for your POC, it’s time to stage data sets that will help demonstrate the capabilities of these identifiers and better understand how ...
1 month ago Aws.amazon.com
DNA testing: What happens if your genetic data is hacked? - The personal information of millions of people who sent swabs of their DNA to consumer testing services have been leaked in high profile hacks in recent years, leading to questions about how secure that genetic data is. In autumn 2023, a hacker ...
8 months ago Packetstormsecurity.com
Microservices Resilient Testing Framework - As organizations increasingly embrace the microservices approach, the need for a resilient testing framework becomes important for the reliability, scalability, and security of these distributed systems. From preemptive problem-solving to the ...
10 months ago Feeds.dzone.com
How Does Automated API Testing Differ from Manual API Testing: Unveiling the Advantages - Delve into automated versus manual API testing for efficient software delivery. See how automation speeds validation while manual testing provides human insight, ensuring comprehensive coverage for robust development. In the domain of software ...
9 months ago Hackread.com
How to do Penetration Testing effectively - In today's digital era, penetration testing has become crucial to an organisation's cybersecurity strategy. From network penetration testing to web application and mobile app penetration testing, a comprehensive pen test covers a wide range of attack ...
5 months ago Securityboulevard.com
23andMe - 23andMe is a revolutionary service that analyzes your DNA and provides insights into your health, ancestry, and traits. This saliva-based DNA service offers personalized reports on your ancestry, family history, traits, and more. With one of the ...
11 months ago
How to Use Pen Testing to Find Vulnerabilities - One effective method for conducting an information security audit is through penetration testing. The contractor would conduct thorough testing and provide detailed penetration reports, complete with recommendations for safeguarding corporate data. ...
9 months ago Feeds.dzone.com
Product showcase: ImmuniWeb AI Platform - ImmuniWeb is a global application security company that currently serves over 1,000 customers from more than 50 countries. ImmuniWeb AI Platform has received numerous prestigious awards and industry recognitions for intelligent automation and ...
10 months ago Helpnetsecurity.com
Hacker leaks millions of new 23andMe genetic data profiles - A hacker has leaked an additional 4.1 million stolen 23andMe genetic data profiles for people in Great Britain and Germany on a hacking forum. Earlier this month, a threat actor leaked the stolen data of 1 million Ashkenazi Jews who used 23andMe ...
11 months ago Bleepingcomputer.com
Application Security Testing Explained - That's precisely why application security is a top priority for security teams and a crucial consideration for DevOps. Application security testing is like giving your software a thorough health check to ensure it's robust and resilient against cyber ...
9 months ago Securityboulevard.com
A Cybersecurity Risk Assessment Guide for Leaders - Now more than ever, keeping your cyber risk in check is crucial. In the first half of 2022's Cyber Risk Index, 85% of the survey's 4,100 global respondents said it's somewhat to very likely they will experience a cyber attack in the next 12 months. ...
1 year ago Trendmicro.com
23andMe failed to detect mega-breach attackers for 5 months The Register - Biotech and DNA-collection biz 23andMe, the one that blamed its own customers for the October mega-breach, just admitted it failed to detect any malicious activity for the entire five months attackers were breaking into user accounts. In a collection ...
9 months ago Go.theregister.com
Bioinformatics: Revolutionizing Healthcare and Research - Bioinformatics plays a crucial role in decoding complex biological data to drive advancements in healthcare and research. In the realm of healthcare technology, bioinformatics is essential for personalized medicine, where treatments are tailored to ...
7 months ago Securityzap.com
How to Temporarily Deactivate Instagram? - Instagram is an amazing social platform where you can stay in touch with your friends and influencers, but sometimes it can be too much. If Instagram has become too distracting or overwhelming for you to use effectively-whether for mental peace, ...
10 months ago Hackercombat.com
Defend Your Business: Testing Your Security Against QakBot and Black Basta Ransomware - Advertising presented to you on this service can be based on limited data, such as the website or app you are using, your non-precise location, your device type or which content you are interacting with. Information about your activity on this ...
5 months ago Securityboulevard.com
DAST Vs. Penetration Testing: Comprehensive Guide to Application Security Testing - Advertising presented to you on this service can be based on limited data, such as the website or app you are using, your non-precise location, your device type or which content you are interacting with. Information about your activity on this ...
4 months ago Securityboulevard.com
New Microsoft Purview features use AI to help secure and govern all your data - More than 90% of organizations use multiple cloud infrastructures, platforms, and services to run their business, adding complexity to securing all data.1Microsoft Purview can help you secure and govern your entire data estate in this complex and ...
10 months ago Microsoft.com
Lee County student Chromebooks hacked in 'Cyber Monday prank' - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
11 months ago Nbc-2.com
YouTube Channels Hacked to Spread Lumma Stealer via Cracked Software - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
9 months ago Hackread.com
SEC X Account Hacked, Tweets Fake News About Bitcoin ETFs - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
9 months ago Hackread.com
Mandiant: X Account Hacked in Brute-Force Attack Linked to ClinkSink Campaign - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
9 months ago Hackread.com
Russian APT29 Hacked US Biomedical Giant in TeamCity-Linked Breach - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
10 months ago Hackread.com
X Account of Google Cybersecurity Firm Mandiant Hacked in Crypto Scam - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
10 months ago Hackread.com
Beirut Airport Screens Hacked with Anti-Hezbollah Message - Cookies, device or similar online identifiers together with other information can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here. Advertising ...
9 months ago Hackread.com
23andMe confirms nearly 7 million customers affected in data leak - Nearly 7 million 23andMe customers had their profile data leaked in a cybersecurity incident in October, a company spokesperson confirmed to SC Media on Monday. The vast majority of the leaked data was scraped from the site's DNA Relatives feature ...
11 months ago Packetstormsecurity.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)