Spain Levies €2.77M Fine Against 23andMe
Spain's Agencia Española de Protección de Datos (AEPD) — the country's data protection authority — has formally fined 23andMe approximately $3 million (roughly €2.77 million) for cybersecurity shortcomings that allowed the company's 2023 data breach to occur. The AEPD's decision, announced Friday, found that more than 2,600 Spanish residents were among the 6.9 million individuals whose data was compromised in the attack.
The 2023 23andMe Breach: Background
In late 2023, threat actors conducted a credential-stuffing campaign against 23andMe — using usernames and passwords leaked from other breached sites to log into accounts where users had reused credentials. The attackers then abused 23andMe's DNA Relatives feature, which allows users to share genetic ancestry data with relatives, to harvest profile data at scale from connected accounts.
Attack Timeline
| Period | Event |
|---|---|
| April–September 2023 | Credential-stuffing attacks began |
| October 2023 | 23andMe publicly disclosed breach |
| December 2023 | Full scope confirmed: 6.9 million users affected |
| 2024–2026 | International regulatory investigations begin |
| July 2026 | Spain (AEPD) issues formal fine |
What Was Exposed
The breach exposed highly sensitive personal information:
- Genetic ancestry data — ethnicity estimates and family tree information
- Health predisposition data — for users who had opted into health reports
- Display names and profile photos
- Relationship labels (parent, sibling, etc.)
- Location data (broad city/region)
Genetic data is classified as a special category of personal data under GDPR, warranting heightened protection and stricter regulatory scrutiny when breached.
AEPD's Findings
The AEPD determined that 23andMe's cybersecurity measures were inadequate given the sensitivity of the data being processed. The regulator's decision centers on failures that enabled the credential-stuffing attack to succeed at scale:
Key AEPD Findings
- Insufficient authentication controls — 23andMe did not mandate multi-factor authentication (MFA) for user accounts at the time of the breach, a significant gap given the sensitivity of genetic data
- Inadequate monitoring — the company failed to detect the credential-stuffing campaign during the months it was ongoing (April–September 2023)
- Disproportionate data sharing — the DNA Relatives feature amplified breach impact by exposing connected users who had not themselves been compromised via credential stuffing
- Special category data risk management — the AEPD found that 23andMe did not apply security measures commensurate with the elevated risk of processing genetic data
Regulatory and Legal Context
GDPR Obligations for Genetic Data
Under the EU's General Data Protection Regulation (GDPR), genetic data is explicitly classified as a special category of personal data (Article 9). Organizations processing such data must:
- Apply enhanced security measures proportionate to the sensitivity
- Conduct Data Protection Impact Assessments (DPIA) for high-risk processing
- Notify regulators within 72 hours of discovering a breach
- Implement appropriate technical and organizational measures to protect data
The AEPD's fine reflects a judgment that 23andMe fell short of these obligations — particularly around the adequacy of security controls for a platform processing genetic data at scale.
Spain's Enforcement Authority
Spain's AEPD is one of the more active EU data protection authorities. The fine is a national-level enforcement action under GDPR's provisions allowing EU member states to independently investigate and penalize companies that process data of their residents.
23andMe's Financial Context
The fine arrives against a fraught backdrop for 23andMe. The company:
- Filed for bankruptcy in March 2025 after years of financial losses
- Was acquired by a new owner following the bankruptcy proceedings
- Faced multiple class-action lawsuits in the US following the 2023 breach
- Has settled US litigation related to the breach
The ~$3 million Spanish fine adds to the company's breach-related financial liabilities, though it is modest relative to the scale of the US settlement and overall breach impact.
Implications for Other Genomics and Health Data Companies
The AEPD action against 23andMe carries broader implications for the direct-to-consumer genomics sector and any company processing health or genetic data:
Key Takeaways
| Lesson | Action Required |
|---|---|
| Credential stuffing is a foreseeable threat | Mandate MFA; monitor for anomalous login patterns |
| Feature amplification can expand breach scope | Apply data minimization to sharing features |
| Genetic data requires elevated controls | Exceed baseline security for special category data |
| EU regulators pursue cross-border breaches | Assume EU authorities will investigate if EU residents are affected |
| Breach detection latency is costly | Invest in continuous authentication monitoring |
Credential-Stuffing Defenses
Recommended Controls:
1. Mandatory MFA for accounts holding sensitive personal data
2. Compromised credential detection (Have I Been Pwned API integration)
3. Rate-limiting and CAPTCHA on login endpoints
4. Behavioral analytics to detect automated login patterns
5. Anomalous access alerts (new IP, new device, unusual hours)
6. Account lockout after repeated failed attempts
What This Means for Users
If you are a 23andMe user whose data was exposed in the 2023 breach:
- Change your password if you have not already — and ensure it is unique to 23andMe
- Enable MFA on your 23andMe account (now available)
- Review your DNA Relatives settings — consider restricting what data is shared with matches
- Monitor for phishing — your email and ancestry data could be used to craft targeted attacks
- Consider whether you want to request data deletion if you no longer use the service
The Record first reported the AEPD's decision. CosmicBytez Labs will update this article as additional EU regulatory actions related to the 23andMe breach emerge.