Spain Fines 23andMe €2.4M for Security Failures in Data Breach

Spain’s data protection authority has imposed a €2.4 million fine on genetic testing company 23andMe for security lapses linked to a 2023 data breach. This incident exposed sensitive information, including genetic, health, ethnicity, and family-related data of over 2,600 individuals in Spain.

The breach resulted from a credential-stuffing attack, where attackers used login credentials obtained from previous third-party breaches to access customer accounts. This method did not exploit vulnerabilities in 23andMe’s core infrastructure but leveraged reused passwords to gain unauthorized access.

Once inside a limited number of accounts, the attackers exploited 23andMe’s social and family-matching features to gather information from a broader user base. Although approximately 14,000 accounts were directly accessed, the interconnected nature of the platform amplified the breach’s impact, affecting millions of profiles.

Spain’s regulatory authority determined that 23andMe failed to implement security controls appropriate for the sensitivity of the data it handled. Genetic data can reveal extensive personal information, making its exposure particularly serious under European privacy regulations. Additionally, the company was found to have delayed notifying authorities after discovering the breach.

Under the EU General Data Protection Regulation (GDPR), organizations must report qualifying personal data breaches to the relevant supervisory authority without undue delay, typically within 72 hours of becoming aware of the incident.

This breach underscores the risks associated with relying solely on passwords for services that store highly sensitive personal information. At the time of the attack, 23andMe did not mandate multi-factor authentication for all users. Security investigators later found that the company lacked robust password protections, did not implement enhanced checks for raw genetic data downloads, and lacked effective systems to detect and respond to threats targeting customer accounts.

Mandatory multi-factor authentication could have significantly reduced the success of credential-stuffing attacks. In such incidents, threat actors automate login attempts using username-password combinations stolen from unrelated breaches. If a reused password is involved, it may grant access even if the targeted company has not directly suffered a network compromise.

The 23andMe case also illustrates how privacy-focused product features can increase the impact of a breach. A single compromised account may expose information about relatives or connections who did not have their own accounts directly accessed. Organizations handling genetic, medical, financial, or identity data should assess the potential “blast radius” of every account takeover scenario.

Spain’s fine follows similar action in the UK, where 23andMe was fined £2.31 million for inadequate security controls protecting sensitive user data.

For security teams, this enforcement action reinforces a clear message: handling sensitive personal data requires robust security measures, including multi-factor authentication and timely breach reporting, to comply with regulatory standards and protect user privacy.