Spain Fines 23andMe €2.4 Million Over 2023 Data Breach


Spain’s data protection authority has fined 23andMe €2.4 million for security and notification failures connected to its major 2023 data breach. The incident exposed personal information belonging to 2,642 people in Spain, including genetic, health and ethnicity data.

The Spanish Data Protection Agency’s enforcement decision imposed a €2 million penalty for failing to protect personal data adequately. It added another €400,000 penalty because 23andMe failed to notify the regulator within the required period.

The Spanish cases formed part of a much larger incident involving approximately 6.9 million profiles worldwide. However, attackers directly accessed only about 14,000 customer accounts before using 23andMe’s connected-family features to reach information associated with millions of other users.

Spain’s 23andMe fine explained

The AEPD found that 23andMe violated Article 5(1)(f) and Article 33 of the General Data Protection Regulation. These provisions cover the integrity and confidentiality of personal data and the requirement to report qualifying breaches promptly.

GDPR violationAEPD findingPenalty
Article 5(1)(f)Failure to provide security appropriate for the sensitive personal data being processed€2 million
Article 33Failure to notify the Spanish regulator within the required period€400,000
TotalCombined administrative fine€2.4 million

The regulator treated the nature of the exposed information as an aggravating factor. The affected records included identity, contact and location details, images, health information, genetic data and information revealing ethnic origin.

Unlike a password or payment card, genetic information cannot simply be replaced after exposure. It can also reveal information about biological relatives who never created an account with the breached service.

How attackers breached 23andMe accounts

The incident began with credential stuffing, an automated attack that tests username and password combinations exposed through unrelated breaches. The attackers succeeded when customers had reused the same login details on 23andMe and other websites.

23andMe said in its security incident action plan that attackers directly accessed fewer than 0.1% of its 14 million customer accounts. This represented approximately 14,000 accounts.

Investigators did not conclude that attackers exploited a vulnerability in 23andMe’s central infrastructure. However, the use of stolen credentials did not remove the company’s responsibility to apply security measures appropriate to the sensitivity and scale of its data.

  • Attackers obtained credentials exposed through previous third-party incidents.
  • They tested those credentials against 23andMe customer accounts.
  • Reused passwords provided access to approximately 14,000 accounts.
  • Connected-family features expanded the amount of information available.
  • Some stolen information appeared online and was offered for sale.

DNA Relatives expanded the breach to millions of profiles

After accessing the initial accounts, the attackers reached profile information shared through 23andMe’s DNA Relatives service. This optional feature connects customers who may share genetic relationships.

Approximately 5.5 million DNA Relatives profiles were accessed. Depending on each person’s settings, the exposed information could include display names, birth years, relationship labels, shared DNA percentages, ancestry reports and self-reported locations.

Attackers also accessed approximately 1.4 million Family Tree profiles connected to the compromised accounts. Family Tree data could include names, birth years, locations and relationship information.

Affected groupApproximate scaleType of exposure
Directly accessed accounts14,000Account information, ancestry details and some health-related information
DNA Relatives profiles5.5 millionAncestry, relationship and profile information shared through DNA Relatives
Family Tree profiles1.4 millionNames, relationships, birth years, locations and sharing information
People affected in Spain2,642Identity, contact, location, health, genetic and ethnicity data

23andMe did not require multi-factor authentication

At the time of the breach, 23andMe allowed customers to protect their accounts with multi-factor authentication, but it did not require them to enable it. Customers could access accounts containing highly sensitive information with only a username and password.

The Spanish regulator also found that 23andMe had not established limits for accessing, requesting or downloading data based on an IP address. Such controls can help identify automated activity and restrict the volume of information collected from compromised accounts.

A separate UK Information Commissioner’s Office investigation identified inadequate authentication and verification controls. The ICO specifically cited the absence of additional verification before customers could access and download raw genetic data.

The company took 12 days to notify Spain

23andMe detected a Reddit post offering purported customer information on October 1, 2023. On October 5, it confirmed that one of the published records belonged to a customer, giving the company reasonable certainty that personal data had been compromised.

The company published a public alert on October 6, notified US authorities on October 7 and began forcing password resets on October 9. It notified customers on October 10 but did not report the breach to the AEPD until October 17.

Article 33 of the EU General Data Protection Regulation requires controllers to report a qualifying personal data breach without undue delay and, where possible, within 72 hours of becoming aware of it. A delayed report must include reasons for the delay.

DateEvent
October 1, 202323andMe detected a Reddit post offering purported customer information.
October 5, 2023The company confirmed that published information belonged to a customer.
October 6, 202323andMe published an alert about the incident.
October 7, 2023The company notified US authorities.
October 9, 202323andMe closed active sessions and required password resets.
October 10, 2023The company emailed customers about the incident.
October 17, 202323andMe notified the Spanish regulator.
October 30, 2023The company expanded its Spanish notification with more affected users.

Why the AEPD rejected the delayed reporting

The AEPD determined that 23andMe became aware of the breach on October 5, when it confirmed that the published information belonged to one of its customers. The October 17 notification therefore came 12 days after that point.

The regulator said prompt reporting is not merely an administrative requirement. Early notification gives authorities an opportunity to support mitigation and reduce potential harm to affected people.

The GDPR allows companies to provide information gradually when they cannot establish every detail within 72 hours. A company does not need to complete its entire forensic investigation before sending an initial notification.

UK previously fined 23andMe £2.31 million

Spain’s action follows a £2.31 million penalty imposed by the UK privacy regulator in June 2025. The UK investigation covered personal information belonging to 155,592 residents.

The ICO found that 23andMe lacked appropriate authentication controls, secure password protocols and adequate systems for monitoring and responding to cyber threats. The regulator conducted its investigation jointly with Canada’s privacy commissioner.

The UK and Spanish decisions both rejected the idea that password reuse alone removed 23andMe’s responsibility. Regulators expected stronger safeguards because the company handled genetic, ancestry and health information at a large scale.

23andMe introduced mandatory authentication after the breach

Following the incident, 23andMe required all customers to reset their passwords. It also made two-step verification mandatory and began requiring customers to confirm their birth dates when signing in.

The company’s post-breach security measures also included session timeouts and tighter restrictions on DNA Relatives information. These changes arrived after attackers had already accessed and published customer data.

The enforcement action shows that companies handling genetic information must plan for account-takeover attacks even when attackers obtain passwords elsewhere. Password screening, mandatory multi-factor authentication, download controls and anomaly detection can all reduce the impact of credential stuffing.

  • Require phishing-resistant multi-factor authentication for every account.
  • Block passwords found in known breach databases.
  • Rate-limit login, data-access and download requests.
  • Require additional verification before releasing raw genetic data.
  • Alert security teams to unusual IP addresses and automated access patterns.
  • Limit how much connected-user information one account can retrieve.
  • Prepare a breach-notification process that can meet the 72-hour deadline.

What the fine means for genetic data companies

The AEPD’s final decision confirms that the €2.4 million total consists of separate penalties for inadequate data security and delayed breach notification. The decision can still face administrative or judicial challenges under Spanish law.

Article 5(1)(f) of the GDPR requires organizations to protect personal information against unauthorized or unlawful processing through appropriate technical and organizational measures.

For genetic testing services, those measures must reflect the permanent and interconnected nature of the information. One compromised account can expose details about many other people, making the possible impact much larger than the number of stolen passwords suggests.

FAQ

Why did Spain fine 23andMe?

Spain fined 23andMe for failing to apply security measures appropriate for sensitive genetic data and for notifying the Spanish regulator after the GDPR deadline.

How much did Spain fine 23andMe?

The total fine was €2.4 million. The AEPD imposed €2 million for inadequate data security and €400,000 for delayed breach notification.

How many people in Spain were affected by the 23andMe breach?

The Spanish regulator identified 2,642 affected people. The exposed information included identity, contact, location, health, genetic and ethnicity data.

Did hackers directly access 6.9 million 23andMe accounts?

No. Attackers directly accessed approximately 14,000 accounts through credential stuffing. They then reached about 5.5 million DNA Relatives profiles and 1.4 million Family Tree profiles connected to those accounts.

What is credential stuffing?

Credential stuffing is an automated attack that tests usernames and passwords stolen from other services. It succeeds when people reuse the same login credentials across multiple websites.

How late was 23andMe’s notification to Spain?

The AEPD determined that 23andMe became aware of the breach on October 5, 2023, but did not notify the Spanish regulator until October 17.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages