Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023.
This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals in Spain.
The penalty follows a significant credential-stuffing attack that compromised data associated with approximately 6.9 million 23andMe users worldwide.
In this attack, intruders used login credentials obtained from previous third-party breaches to access customer accounts, rather than exploiting a vulnerability in 23andMe’s core infrastructure.
Spain Fines 23andMe Over User Breach
Once the attackers gained access to a limited number of accounts, they abused 23andMe’s social and family-matching features to gather information from a much larger group of users.
While the company reported that around 14,000 accounts were directly accessed, the relationships established through account connections and DNA-relative features amplified the breach’s impact, affecting millions of profiles.
Spain’s regulatory authority concluded that 23andMe had not implemented security controls that were appropriate for the extreme sensitivity of the data it handled.
Genetic data can reveal family connections, ancestry, health insights, and ethnicity, making its exposure especially serious under European privacy regulations. The authority also found that the company notified them too late after discovering the breach.
According to the EU General Data Protection Regulation (GDPR), organizations must report qualifying personal data breaches to the relevant supervisory authority without undue delay, typically within 72 hours of becoming aware of the incident.
This breach highlighted the risks associated with relying solely on passwords for services that hold highly valuable personal information. At the time of the attack, 23andMe did not require multi-factor authentication for all users.
Security investigators later discovered that the company also lacked sufficiently strong password protections, failed to implement enhanced checks for raw genetic data downloads, and did not have effective systems in place to detect and respond to threats targeting customer accounts.
Mandatory multi-factor authentication could have significantly reduced the success of credential stuffing attacks. In these incidents, threat actors automate login attempts using username-password combinations stolen from unrelated breaches.
If a reused password is involved, it may grant access even if the targeted company has not directly suffered a network compromise. The 23andMe case also illustrates how privacy-focused product features can increase the impact of a breach.
A single compromised account may expose information about relatives or connections who did not have their own accounts directly accessed.
Organizations that handle genetic, medical, financial, or identity data should therefore assess the potential “blast radius” of every account takeover scenario.
Spain’s fine follows similar action in the UK, where 23andMe was fined £2.31 million for inadequate security controls protecting sensitive user data.
For security teams, this enforcement action reinforces a clear message: high-risk data environments require phishing-resistant authentication, breached-password screening, anomaly detection, robust download controls, and rapid incident reporting.
The consequences of inadequate identity security can extend far beyond a direct account compromise when interconnected user data is involved.
The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment
The post Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach appeared first on Cyber Security News.
Abinaya
Go to cyber-security-news