23andMe failed to implement basic security protections before a 2023 cyberattack compromised the sensitive data of nearly 7 million users, according to privacy watchdogs in Canada and the UK.
A joint probe by Canada’s Privacy Commissioner Philippe Dufresne and UK Information Commissioner John Edwards concluded that the company’s security systems were inadequate and that it was slow to act on early warning signs. The breach affected about 320,000 Canadians and more than 150,000 people in the UK, exposing genetic data and personal ancestry information.
Dufresne called the incident a “cautionary tale” for organizations handling sensitive data, pointing to the lack of multi-factor authentication and weak password requirements as key failures.
The breach marked the start of a steep decline for the California-based company. Its market value has plunged over 97% since going public, and all seven of its independent directors resigned in September 2023.
In March, 23andMe filed for bankruptcy amid declining consumer demand and fallout from the breach. Regeneron Pharmaceuticals later offered $256 million to acquire the company but withdrew its bid on Monday after 23andMe co-founder Anne Wojcicki submitted a competing offer through her nonprofit, TTAM Research Institute.
Wojcicki’s $305 million bid is expected to close following court approval. TTAM said it would uphold 23andMe’s existing privacy commitments and adhere to all applicable data protection laws.