Spain Fines 23andMe €2.4 Million Over 2023 Data Breach
Spain’s data protection authority has fined 23andMe €2.4 million for security and notification failures connected to its major 2023 data breach. The incident exposed personal information belonging to 2,642 people in Spain, including genetic, health and ethnicity data.
The Spanish Data Protection Agency’s enforcement decision imposed a €2 million penalty for failing to protect personal data adequately. It added another €400,000 penalty because 23andMe failed to notify the regulator within the required period.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The Spanish cases formed part of a much larger incident involving approximately 6.9 million profiles worldwide. However, attackers directly accessed only about 14,000 customer accounts before using 23andMe’s connected-family features to reach information associated with millions of other users.
Spain’s 23andMe fine explained
The AEPD found that 23andMe violated Article 5(1)(f) and Article 33 of the General Data Protection Regulation. These provisions cover the integrity and confidentiality of personal data and the requirement to report qualifying breaches promptly.
| GDPR violation | AEPD finding | Penalty |
|---|---|---|
| Article 5(1)(f) | Failure to provide security appropriate for the sensitive personal data being processed | €2 million |
| Article 33 | Failure to notify the Spanish regulator within the required period | €400,000 |
| Total | Combined administrative fine | €2.4 million |
The regulator treated the nature of the exposed information as an aggravating factor. The affected records included identity, contact and location details, images, health information, genetic data and information revealing ethnic origin.
Unlike a password or payment card, genetic information cannot simply be replaced after exposure. It can also reveal information about biological relatives who never created an account with the breached service.
How attackers breached 23andMe accounts
The incident began with credential stuffing, an automated attack that tests username and password combinations exposed through unrelated breaches. The attackers succeeded when customers had reused the same login details on 23andMe and other websites.
23andMe said in its security incident action plan that attackers directly accessed fewer than 0.1% of its 14 million customer accounts. This represented approximately 14,000 accounts.
Investigators did not conclude that attackers exploited a vulnerability in 23andMe’s central infrastructure. However, the use of stolen credentials did not remove the company’s responsibility to apply security measures appropriate to the sensitivity and scale of its data.
- Attackers obtained credentials exposed through previous third-party incidents.
- They tested those credentials against 23andMe customer accounts.
- Reused passwords provided access to approximately 14,000 accounts.
- Connected-family features expanded the amount of information available.
- Some stolen information appeared online and was offered for sale.
DNA Relatives expanded the breach to millions of profiles
After accessing the initial accounts, the attackers reached profile information shared through 23andMe’s DNA Relatives service. This optional feature connects customers who may share genetic relationships.
Approximately 5.5 million DNA Relatives profiles were accessed. Depending on each person’s settings, the exposed information could include display names, birth years, relationship labels, shared DNA percentages, ancestry reports and self-reported locations.
Attackers also accessed approximately 1.4 million Family Tree profiles connected to the compromised accounts. Family Tree data could include names, birth years, locations and relationship information.
| Affected group | Approximate scale | Type of exposure |
|---|---|---|
| Directly accessed accounts | 14,000 | Account information, ancestry details and some health-related information |
| DNA Relatives profiles | 5.5 million | Ancestry, relationship and profile information shared through DNA Relatives |
| Family Tree profiles | 1.4 million | Names, relationships, birth years, locations and sharing information |
| People affected in Spain | 2,642 | Identity, contact, location, health, genetic and ethnicity data |
23andMe did not require multi-factor authentication
At the time of the breach, 23andMe allowed customers to protect their accounts with multi-factor authentication, but it did not require them to enable it. Customers could access accounts containing highly sensitive information with only a username and password.
The Spanish regulator also found that 23andMe had not established limits for accessing, requesting or downloading data based on an IP address. Such controls can help identify automated activity and restrict the volume of information collected from compromised accounts.
A separate UK Information Commissioner’s Office investigation identified inadequate authentication and verification controls. The ICO specifically cited the absence of additional verification before customers could access and download raw genetic data.
The company took 12 days to notify Spain
23andMe detected a Reddit post offering purported customer information on October 1, 2023. On October 5, it confirmed that one of the published records belonged to a customer, giving the company reasonable certainty that personal data had been compromised.
The company published a public alert on October 6, notified US authorities on October 7 and began forcing password resets on October 9. It notified customers on October 10 but did not report the breach to the AEPD until October 17.
Article 33 of the EU General Data Protection Regulation requires controllers to report a qualifying personal data breach without undue delay and, where possible, within 72 hours of becoming aware of it. A delayed report must include reasons for the delay.
| Date | Event |
|---|---|
| October 1, 2023 | 23andMe detected a Reddit post offering purported customer information. |
| October 5, 2023 | The company confirmed that published information belonged to a customer. |
| October 6, 2023 | 23andMe published an alert about the incident. |
| October 7, 2023 | The company notified US authorities. |
| October 9, 2023 | 23andMe closed active sessions and required password resets. |
| October 10, 2023 | The company emailed customers about the incident. |
| October 17, 2023 | 23andMe notified the Spanish regulator. |
| October 30, 2023 | The company expanded its Spanish notification with more affected users. |
Why the AEPD rejected the delayed reporting
The AEPD determined that 23andMe became aware of the breach on October 5, when it confirmed that the published information belonged to one of its customers. The October 17 notification therefore came 12 days after that point.
The regulator said prompt reporting is not merely an administrative requirement. Early notification gives authorities an opportunity to support mitigation and reduce potential harm to affected people.
The GDPR allows companies to provide information gradually when they cannot establish every detail within 72 hours. A company does not need to complete its entire forensic investigation before sending an initial notification.
UK previously fined 23andMe £2.31 million
Spain’s action follows a £2.31 million penalty imposed by the UK privacy regulator in June 2025. The UK investigation covered personal information belonging to 155,592 residents.
The ICO found that 23andMe lacked appropriate authentication controls, secure password protocols and adequate systems for monitoring and responding to cyber threats. The regulator conducted its investigation jointly with Canada’s privacy commissioner.
The UK and Spanish decisions both rejected the idea that password reuse alone removed 23andMe’s responsibility. Regulators expected stronger safeguards because the company handled genetic, ancestry and health information at a large scale.
23andMe introduced mandatory authentication after the breach
Following the incident, 23andMe required all customers to reset their passwords. It also made two-step verification mandatory and began requiring customers to confirm their birth dates when signing in.
The company’s post-breach security measures also included session timeouts and tighter restrictions on DNA Relatives information. These changes arrived after attackers had already accessed and published customer data.
The enforcement action shows that companies handling genetic information must plan for account-takeover attacks even when attackers obtain passwords elsewhere. Password screening, mandatory multi-factor authentication, download controls and anomaly detection can all reduce the impact of credential stuffing.
- Require phishing-resistant multi-factor authentication for every account.
- Block passwords found in known breach databases.
- Rate-limit login, data-access and download requests.
- Require additional verification before releasing raw genetic data.
- Alert security teams to unusual IP addresses and automated access patterns.
- Limit how much connected-user information one account can retrieve.
- Prepare a breach-notification process that can meet the 72-hour deadline.
What the fine means for genetic data companies
The AEPD’s final decision confirms that the €2.4 million total consists of separate penalties for inadequate data security and delayed breach notification. The decision can still face administrative or judicial challenges under Spanish law.
Article 5(1)(f) of the GDPR requires organizations to protect personal information against unauthorized or unlawful processing through appropriate technical and organizational measures.
For genetic testing services, those measures must reflect the permanent and interconnected nature of the information. One compromised account can expose details about many other people, making the possible impact much larger than the number of stolen passwords suggests.
FAQ
Spain fined 23andMe for failing to apply security measures appropriate for sensitive genetic data and for notifying the Spanish regulator after the GDPR deadline.
The total fine was €2.4 million. The AEPD imposed €2 million for inadequate data security and €400,000 for delayed breach notification.
The Spanish regulator identified 2,642 affected people. The exposed information included identity, contact, location, health, genetic and ethnicity data.
No. Attackers directly accessed approximately 14,000 accounts through credential stuffing. They then reached about 5.5 million DNA Relatives profiles and 1.4 million Family Tree profiles connected to those accounts.
Credential stuffing is an automated attack that tests usernames and passwords stolen from other services. It succeeds when people reuse the same login credentials across multiple websites.
The AEPD determined that 23andMe became aware of the breach on October 5, 2023, but did not notify the Spanish regulator until October 17.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages