You can’t reset your DNA like a password
The fact of the matter is that when one of your passwords is leaked, you reset it, and when one of your credit cards is stolen, you can cancel and replace it.
However, when your personal genetic data is exposed to dubious sources, you’ll have to live with that forever.
The 2023 genetic data breach (23andMe) was widely framed as just a data breach about personal credentials instead of a system hack. Well, that framing may be politically, communicatively, and technically convenient, but strategically, it is absolutely incomplete.
It was a governance failure that involved permanent, personal biological data. This was never simply a login issue; it’s much worse! Learn more here:
23andMe
In the fall of 2023, credential stuffing techniques were used by criminal attackers to access and compromise tens of thousands of online accounts, while using passwords from earlier unrelated data breaches.
Initially, the access involved individual accounts, but it appeared that the exposure expanded through the feature “DNA Relatives.”
The ripple effect this caused was staggering and should have caused serious concern. Through interconnected personal genetic profiles, the criminal attackers now had access to much personal data.
This breach was not just about criminals acquiring random data. It was a lot worse, since it could lead to a serious strategic exploitation of lots of personal and relational biometric data regarding:
- individuals’ names
- birth dates
- personal geographic data
- ancestry data and related information
- genetic relative data and connections
This was more than just “Credential Stuffing”
Credential stuffing is actually a foreseeable threat. It is among the best-understood and most common attack vectors in everything related to consumer technology.
The notion that earlier used passwords could impact a genetic testing site was no speculation, it was a predictable act.
However, personal genetic data is not simply a username; it’s a permanent personal biometric identity. You can’t change it!
And the fact of the matter was that multi-factor authentication, at that time, was not a mandatory requirement by default, and for a platform designed to commercialize DNA data, this is not simply a user failure; it nis a design decision with huge consequences!
Under European Law, organizations are required to implement appropriate security measures in relation to the risk of processing the data, and this applies to more risk frameworks.
When the data processing involves personal genetic data (a special category as explicitly classified under GPDR Article 9), the risk threshold is serious, not ordinary.
The Real Risk: Network DNA
Genetic data concerns inherently relational personal information. One single user profile relates to information about siblings, parents, extended family, or future descendants.
So, the greatest risk, the most dangerous aspect of the 23andME breach was not about the number of accounts the criminals accessed. The real risk was the wider network effect.
When one single account was accessed and compromised, all related and linked profiles would become visible, meaning that if one weak password would expose one single account, an complete family network could be compromised.
Genetic data platforms function are pert of shared biological infrastructures, and are required by Law (GDPR Article 35) to account for any risks of cascade exposure. Risk platforms (as is the case here) that identify users as individual data subjects, they are wrong and their systems incomplete.
Consent?
Genetic data isn’t solely individual. It contains, by nature, biological information about relatives who may never have submitted their data to any platform.
This raises the question whether the “consent” declaration was obtained legally correct. Users of the DNA Relatives platform were not always aware that their genetic profile would expose family members data as well, could reveal relationships and visibility beyond any individual.
Organizations are required by Law to to provide information in clear language on how they process personal data, and when it concerns genetic data, the requirements are specifically even higher.
Therefore, the issue is not whether consent was granted. That’s simply too easy. It is about whether and how the genetic data are processed and meaningfully communicated.
Stronger Security Controls
Organizations that process personal, biometric, genetic, or any other special category of data, must have baseline controls in order.</
The fact is that high-risk personal data categories simply require very strong security controls that go beyond consumer-technology baselines.
Multi-step authentication should not be optional but mandatory, and these high-risk platforms must have an automated credential reuse detection system. Additionally, high-risk platforms must provide mandatory stepped-up verification.
Permanent data means permanent safeguards. That doesn’t need any further discussion, right? When your personal data is permanent on a platform, the least you could ask for is that the security features are permanent as well.
As stated earlier: passwords expire, DNA will not. If your personal data is immutable, it asks for sustained, elevated safeguards.
The 23andMe data breach on personal, genetic information has clarified a fundamental aspect of contemporary data risk: there is data that cannot be changed or remediated once it has been exposed, and that requires more elevated security protocols.
When commercial parties commercialize our personal genetic data, they not only store our preferences: they are storing our biological identities and everything related to that.
This special category of data demands the highest possible security controls since our networked biometric data can multiply harm far beyond us as individual users.