Spain Fines 23andMe €2.4M for 6.9M User Data Breach
Key Takeaways Genetic testing firm 23andMe has been fined €2.4 million by Spain’s data protection authority. The penalty stems from a 2023 data breach that exposed sensitive genetic and health...
Key Takeaways
- Genetic testing firm 23andMe has been fined €2.4 million by Spain’s data protection authority.
- The penalty stems from a 2023 data breach that exposed sensitive genetic and health information for approximately 6.9 million users globally, including over 2,600 in Spain.
- The breach was initiated by a credential stuffing attack, exploiting reused passwords, and was exacerbated by insufficient security controls and delayed breach notification.
Spain Penalizes 23andMe for 2023 Data Breach
Spain’s data protection agency has levied a substantial €2.4 million fine against genetic testing giant 23andMe. The penalty is a direct consequence of security failures that contributed to a significant data breach in 2023, which compromised highly sensitive personal information.
Table Of Content
The incident led to the exposure of genetic profiles, health data, ethnicity details, and family relationship information belonging to more than 2,600 individuals residing in Spain. Globally, the breach impacted approximately 6.9 million 23andMe users.
The Nature of the Attack
The breach originated from a credential stuffing attack. Threat actors leveraged login credentials previously stolen from unrelated third-party breaches to gain unauthorized access to customer accounts. Crucially, this attack did not exploit a vulnerability within 23andMe’s core infrastructure but rather relied on users reusing passwords across multiple online services.
While 23andMe reported that around 14,000 user accounts were directly accessed by the attackers, the impact was dramatically amplified by the company’s social and family-matching features. Once inside a limited number of accounts, the perpetrators exploited these features to harvest data from a much larger pool of connected users, ultimately affecting millions of profiles.
Regulatory Findings and Deficiencies
Spain’s regulatory authority concluded that 23andMe had failed to implement adequate security controls, particularly given the extreme sensitivity of the genetic and health data it manages. Genetic information, which can reveal ancestry, family connections, and predispositions to health conditions, is considered among the most sensitive categories of personal data under European privacy regulations, making its exposure particularly severe.
The authority also cited the company for its delayed notification of the breach. Under the EU General Data Protection Regulation (GDPR), organizations are mandated to report qualifying personal data breaches to the relevant supervisory authority without undue delay, typically within 72 hours of discovery.
Investigations revealed several critical security shortcomings at 23andMe at the time of the incident. These included a lack of mandatory multi-factor authentication (MFA) for all users, inadequate password protection measures, insufficient enhanced checks for downloads of raw genetic data, and ineffective systems for detecting and responding to account-targeting threats.
The absence of mandatory MFA was a key factor in the success of the credential stuffing attack. MFA would have provided a crucial additional layer of security, making it significantly harder for attackers to gain access even with stolen passwords. The 23andMe case underscores how privacy-centric product features, such as DNA-relative matching, can inadvertently expand the “blast radius” of a breach, allowing a single compromised account to expose data related to numerous interconnected individuals.
This fine from Spain follows a similar penalty in the UK, where 23andMe was fined £2.31 million for comparable security deficiencies related to sensitive user data.
What You Should Do
- Enable Multi-Factor Authentication (MFA): Implement MFA across all critical online services, especially those holding sensitive personal data.
- Use Unique, Strong Passwords: Avoid reusing passwords. Utilize a reputable password manager to generate and store unique, complex passwords for each account.
- Monitor Account Activity: Regularly review account activity logs for any suspicious or unauthorized access attempts.
- Be Wary of Phishing: Exercise caution with unsolicited emails or messages requesting login credentials or personal information.
- Stay Informed: Be aware of data breach notifications from services you use and follow recommended security actions promptly.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.