Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1999+ Articles
152+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack
Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack
NEWS

Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack

Spain's data protection agency AEPD has fined 23andMe approximately $3 million for cybersecurity failures that enabled the 2023 credential-stuffing breach affecting 6.9 million users worldwide, including over 2,600 Spaniards.

Dylan H.

News Desk

July 21, 2026
5 min read

Spain Levies €2.77M Fine Against 23andMe

Spain's Agencia Española de Protección de Datos (AEPD) — the country's data protection authority — has formally fined 23andMe approximately $3 million (roughly €2.77 million) for cybersecurity shortcomings that allowed the company's 2023 data breach to occur. The AEPD's decision, announced Friday, found that more than 2,600 Spanish residents were among the 6.9 million individuals whose data was compromised in the attack.


The 2023 23andMe Breach: Background

In late 2023, threat actors conducted a credential-stuffing campaign against 23andMe — using usernames and passwords leaked from other breached sites to log into accounts where users had reused credentials. The attackers then abused 23andMe's DNA Relatives feature, which allows users to share genetic ancestry data with relatives, to harvest profile data at scale from connected accounts.

Attack Timeline

PeriodEvent
April–September 2023Credential-stuffing attacks began
October 202323andMe publicly disclosed breach
December 2023Full scope confirmed: 6.9 million users affected
2024–2026International regulatory investigations begin
July 2026Spain (AEPD) issues formal fine

What Was Exposed

The breach exposed highly sensitive personal information:

  • Genetic ancestry data — ethnicity estimates and family tree information
  • Health predisposition data — for users who had opted into health reports
  • Display names and profile photos
  • Relationship labels (parent, sibling, etc.)
  • Location data (broad city/region)

Genetic data is classified as a special category of personal data under GDPR, warranting heightened protection and stricter regulatory scrutiny when breached.


AEPD's Findings

The AEPD determined that 23andMe's cybersecurity measures were inadequate given the sensitivity of the data being processed. The regulator's decision centers on failures that enabled the credential-stuffing attack to succeed at scale:

Key AEPD Findings

  1. Insufficient authentication controls — 23andMe did not mandate multi-factor authentication (MFA) for user accounts at the time of the breach, a significant gap given the sensitivity of genetic data
  2. Inadequate monitoring — the company failed to detect the credential-stuffing campaign during the months it was ongoing (April–September 2023)
  3. Disproportionate data sharing — the DNA Relatives feature amplified breach impact by exposing connected users who had not themselves been compromised via credential stuffing
  4. Special category data risk management — the AEPD found that 23andMe did not apply security measures commensurate with the elevated risk of processing genetic data

Regulatory and Legal Context

GDPR Obligations for Genetic Data

Under the EU's General Data Protection Regulation (GDPR), genetic data is explicitly classified as a special category of personal data (Article 9). Organizations processing such data must:

  • Apply enhanced security measures proportionate to the sensitivity
  • Conduct Data Protection Impact Assessments (DPIA) for high-risk processing
  • Notify regulators within 72 hours of discovering a breach
  • Implement appropriate technical and organizational measures to protect data

The AEPD's fine reflects a judgment that 23andMe fell short of these obligations — particularly around the adequacy of security controls for a platform processing genetic data at scale.

Spain's Enforcement Authority

Spain's AEPD is one of the more active EU data protection authorities. The fine is a national-level enforcement action under GDPR's provisions allowing EU member states to independently investigate and penalize companies that process data of their residents.


23andMe's Financial Context

The fine arrives against a fraught backdrop for 23andMe. The company:

  • Filed for bankruptcy in March 2025 after years of financial losses
  • Was acquired by a new owner following the bankruptcy proceedings
  • Faced multiple class-action lawsuits in the US following the 2023 breach
  • Has settled US litigation related to the breach

The ~$3 million Spanish fine adds to the company's breach-related financial liabilities, though it is modest relative to the scale of the US settlement and overall breach impact.


Implications for Other Genomics and Health Data Companies

The AEPD action against 23andMe carries broader implications for the direct-to-consumer genomics sector and any company processing health or genetic data:

Key Takeaways

LessonAction Required
Credential stuffing is a foreseeable threatMandate MFA; monitor for anomalous login patterns
Feature amplification can expand breach scopeApply data minimization to sharing features
Genetic data requires elevated controlsExceed baseline security for special category data
EU regulators pursue cross-border breachesAssume EU authorities will investigate if EU residents are affected
Breach detection latency is costlyInvest in continuous authentication monitoring

Credential-Stuffing Defenses

Recommended Controls:
1. Mandatory MFA for accounts holding sensitive personal data
2. Compromised credential detection (Have I Been Pwned API integration)
3. Rate-limiting and CAPTCHA on login endpoints
4. Behavioral analytics to detect automated login patterns
5. Anomalous access alerts (new IP, new device, unusual hours)
6. Account lockout after repeated failed attempts

What This Means for Users

If you are a 23andMe user whose data was exposed in the 2023 breach:

  • Change your password if you have not already — and ensure it is unique to 23andMe
  • Enable MFA on your 23andMe account (now available)
  • Review your DNA Relatives settings — consider restricting what data is shared with matches
  • Monitor for phishing — your email and ancestry data could be used to craft targeted attacks
  • Consider whether you want to request data deletion if you no longer use the service

The Record first reported the AEPD's decision. CosmicBytez Labs will update this article as additional EU regulatory actions related to the 23andMe breach emerge.

Related Reading

  • 23andMe Bankruptcy and Data Fate — What Users Need to Know
  • Italy Fines Financial Firm €36M for Data Protection Failures
#Data Breach#GDPR#Regulatory Fine#23andMe#Privacy#Spain#Genetic Data

Related Articles

California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

California Attorney General Rob Bonta filed a lawsuit against 23andMe — now Chrome Holding Co. — over its failure to protect millions of customers'...

6 min read

23andMe to Pay $18 Million in New Genetics Data Breach Settlement

Genetic testing company 23andMe has agreed to pay $18 million to settle claims from 43 attorneys general that it failed to adequately protect customers'...

4 min read

23andMe $47 Million Settlement Approved for 7 Million Breach Victims

A bankruptcy administrator has approved a $47 million settlement fund for roughly 7 million 23andMe customers whose genetic and health data was stolen by...

4 min read
Back to all News