Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns of Actively Exploited Critical WordPress Core SQL Injection Flaw
July 22, 2026
FBI Warns of AI Deepfake Scams and Fake IC3 Sites Targeting Fraud Victims
July 22, 2026
Critical Zimbra CVE-2024-28902 flaw lets attackers inject commands
July 22, 2026
Home/CyberSecurity News/Spain Fines 23andMe €2.4M for 6.9M User Data Breach
CyberSecurity News

Spain Fines 23andMe €2.4M for 6.9M User Data Breach

Key Takeaways Genetic testing firm 23andMe has been fined €2.4 million by Spain’s data protection authority. The penalty stems from a 2023 data breach that exposed sensitive genetic and health...

Jennifer sherman
Jennifer sherman
July 22, 2026 3 Min Read
3 0

Key Takeaways

  • Genetic testing firm 23andMe has been fined €2.4 million by Spain’s data protection authority.
  • The penalty stems from a 2023 data breach that exposed sensitive genetic and health information for approximately 6.9 million users globally, including over 2,600 in Spain.
  • The breach was initiated by a credential stuffing attack, exploiting reused passwords, and was exacerbated by insufficient security controls and delayed breach notification.

Spain Penalizes 23andMe for 2023 Data Breach

Spain’s data protection agency has levied a substantial €2.4 million fine against genetic testing giant 23andMe. The penalty is a direct consequence of security failures that contributed to a significant data breach in 2023, which compromised highly sensitive personal information.

Table Of Content

  • Key Takeaways
  • Spain Penalizes 23andMe for 2023 Data Breach
  • The Nature of the Attack
  • Regulatory Findings and Deficiencies
  • What You Should Do

The incident led to the exposure of genetic profiles, health data, ethnicity details, and family relationship information belonging to more than 2,600 individuals residing in Spain. Globally, the breach impacted approximately 6.9 million 23andMe users.

The Nature of the Attack

The breach originated from a credential stuffing attack. Threat actors leveraged login credentials previously stolen from unrelated third-party breaches to gain unauthorized access to customer accounts. Crucially, this attack did not exploit a vulnerability within 23andMe’s core infrastructure but rather relied on users reusing passwords across multiple online services.

While 23andMe reported that around 14,000 user accounts were directly accessed by the attackers, the impact was dramatically amplified by the company’s social and family-matching features. Once inside a limited number of accounts, the perpetrators exploited these features to harvest data from a much larger pool of connected users, ultimately affecting millions of profiles.

Regulatory Findings and Deficiencies

Spain’s regulatory authority concluded that 23andMe had failed to implement adequate security controls, particularly given the extreme sensitivity of the genetic and health data it manages. Genetic information, which can reveal ancestry, family connections, and predispositions to health conditions, is considered among the most sensitive categories of personal data under European privacy regulations, making its exposure particularly severe.

The authority also cited the company for its delayed notification of the breach. Under the EU General Data Protection Regulation (GDPR), organizations are mandated to report qualifying personal data breaches to the relevant supervisory authority without undue delay, typically within 72 hours of discovery.

Investigations revealed several critical security shortcomings at 23andMe at the time of the incident. These included a lack of mandatory multi-factor authentication (MFA) for all users, inadequate password protection measures, insufficient enhanced checks for downloads of raw genetic data, and ineffective systems for detecting and responding to account-targeting threats.

The absence of mandatory MFA was a key factor in the success of the credential stuffing attack. MFA would have provided a crucial additional layer of security, making it significantly harder for attackers to gain access even with stolen passwords. The 23andMe case underscores how privacy-centric product features, such as DNA-relative matching, can inadvertently expand the “blast radius” of a breach, allowing a single compromised account to expose data related to numerous interconnected individuals.

This fine from Spain follows a similar penalty in the UK, where 23andMe was fined £2.31 million for comparable security deficiencies related to sensitive user data.

What You Should Do

  • Enable Multi-Factor Authentication (MFA): Implement MFA across all critical online services, especially those holding sensitive personal data.
  • Use Unique, Strong Passwords: Avoid reusing passwords. Utilize a reputable password manager to generate and store unique, complex passwords for each account.
  • Monitor Account Activity: Regularly review account activity logs for any suspicious or unauthorized access attempts.
  • Be Wary of Phishing: Exercise caution with unsolicited emails or messages requesting login credentials or personal information.
  • Stay Informed: Be aware of data breach notifications from services you use and follow recommended security actions promptly.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Yubico YubiKey 5.8 Update Adds Secure Enterprise Workflows

Next Post

Hackers Steal Microsoft 365 Sessions Via Compromised Outlook Accounts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Steal Microsoft 365 Sessions Via Compromised Outlook Accounts
July 22, 2026
Spain Fines 23andMe €2.4M for 6.9M User Data Breach
July 22, 2026
Yubico YubiKey 5.8 Update Adds Secure Enterprise Workflows
July 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us