Tue 21 Jul 2026 / 16:29 ET
Kernel
Security 3 min read

Spain fines 23andMe €2.4 million over 2023 data breach

Spain’s privacy regulator said weak account protections helped enable a breach that exposed data tied to 6.9 million 23andMe users.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Spain fines 23andMe €2.4 million over 2023 data breach
img: The Record

Spain’s data protection authority has fined 23andMe €2.4 million, about $2.7 million, after finding that the genetic testing company lacked basic safeguards before a 2023 breach that affected 6.9 million people worldwide.

The Agencia Española de Protección de Datos, or AEPD, announced the penalty Friday. In its enforcement decision, the regulator said more than 2,600 people in Spain were affected by the incident.

The case turns on a familiar and preventable failure: attackers used credential stuffing, a technique that tries login details stolen from other services against a target site. AEPD said 23andMe did not require multifactor authentication at the time, a control that can stop many reused-password attacks from becoming account takeovers. The regulator also said the company failed to set limits on access, requests or downloads by IP address.

Those findings are sharper because the data involved was not ordinary account metadata. 23andMe holds genetic and ancestry information, the kind of personal data that GDPR treats as highly sensitive. AEPD said the company’s cybersecurity practices and safeguards did not meet the European privacy law’s requirements.

Regulator says Reddit post alerted the company

According to AEPD’s decision, 23andMe executives learned of the April 2023 breach after someone attempted to sell a sample of the stolen data on Reddit. The regulator said the company then waited 12 days before notifying Spanish officials.

AEPD described prompt notification as material to damage control, saying early reporting was needed for mitigation. Under GDPR, companies handling personal data can face penalties when security controls are inadequate or when regulators are not notified on time after certain breaches.

The decision also examined 23andMe’s own public warnings about cyber risk. AEPD cited a May 2023 fiscal report on the company’s website in which 23andMe discussed ransomware, targeted cybercrime and the risks those threats posed to the confidentiality, availability and integrity of its data.

That report said a security or privacy incident exposing customer data could force 23andMe to comply with breach notification laws, spend money on remediation, address potential insurance increases, and pay for audits or forensic investigations, according to the Spanish decision.

Password policy drew scrutiny

AEPD also faulted the way 23andMe described account credentials to customers. The regulator said the company’s privacy policy mentioned access credentials only once and did not specify password-strength requirements or require periodic password changes.

Password rotation rules are hardly a cure-all, and security engineers have long argued that forced changes can backfire when users choose weaker patterns. In this case, AEPD’s criticism was broader: for a company holding genetic data, the regulator found that 23andMe had not imposed enough account-level friction to reduce credential-stuffing risk.

The Spanish penalty follows a separate U.S. settlement. On July 15, 23andMe reached an $18 million agreement with a coalition of 42 state attorneys general over the breach. As part of that settlement, the company pledged new data protection measures at 23andMe Research Institute, a nonprofit spinoff led by former 23andMe chief executive Anne Wojcicki.

The Spanish decision adds another regulatory bill to the 2023 incident. It also gives a plain lesson to companies sitting on sensitive data: if attackers can walk through reused passwords at scale, regulators may treat missing multifactor authentication and weak rate limits as more than an unfortunate oversight.

This story draws on original reporting from The Record.

More Security/

view all ↗