{"id":14484,"date":"2026-07-22T10:03:43","date_gmt":"2026-07-22T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/22\/spain-fines-23andme-e2-4-million-over-security-failures-behind-6-9-million-user-breach\/"},"modified":"2026-07-22T10:03:43","modified_gmt":"2026-07-22T10:03:43","slug":"spain-fines-23andme-e2-4-million-over-security-failures-behind-6-9-million-user-breach","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/22\/spain-fines-23andme-e2-4-million-over-security-failures-behind-6-9-million-user-breach\/","title":{"rendered":"Spain Fines 23andMe \u20ac2.4 Million Over Security Failures Behind 6.9 Million-User Breach"},"content":{"rendered":"<p>    Spain Fines 23andMe \u20ac2.4 Million Over Security Failures Behind 6.9 Million-User Breach<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Spain\u2019s data protection authority has fined the <a href=\"https:\/\/cybersecuritynews.com\/investigation-over-23andme-hack\/\" target=\"_blank\" rel=\"noreferrer noopener\">genetic testing company 23andMe<\/a> \u20ac2.4 million due to security failures linked to a data breach in 2023.<\/p>\n<p class=\"wp-block-paragraph\">This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals in Spain.<\/p>\n<p class=\"wp-block-paragraph\">The penalty follows a significant <a href=\"https:\/\/cybersecuritynews.com\/north-face-fashion-brand\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential-stuffing attack<\/a> that compromised data associated with approximately 6.9 million 23andMe users worldwide.<\/p>\n<p class=\"wp-block-paragraph\">In this attack, intruders used login credentials obtained from previous third-party breaches to access customer accounts, rather than exploiting a vulnerability in 23andMe\u2019s core infrastructure.<\/p>\n<h2 id=\"h-spain-fines-23andme-over-user-breach\" class=\"wp-block-heading\"><strong>Spain Fines 23andMe  Over User Breach<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Once the attackers gained access to a limited number of accounts, they <a href=\"https:\/\/cybersecuritynews.com\/investigation-over-23andme-hack\/\" target=\"_blank\" rel=\"noreferrer noopener\">abused 23andMe\u2019s<\/a> social and family-matching features to gather information from a much larger group of users.<\/p>\n<p class=\"wp-block-paragraph\">While the company reported that around 14,000 accounts were directly accessed, the relationships established through account connections and DNA-relative features amplified the breach\u2019s impact, affecting millions of profiles.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.aepd.es\/documento\/ps-00140-2025.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Spain\u2019s regulatory authority concluded<\/a> that 23andMe had not implemented security controls that were appropriate for the extreme sensitivity of the data it handled.<\/p>\n<p class=\"wp-block-paragraph\">Genetic data can reveal family connections, ancestry, health insights, and ethnicity, making its exposure especially serious under European privacy regulations. The authority also found that the company notified them too late after discovering the breach.<\/p>\n<p class=\"wp-block-paragraph\">According to the EU <a href=\"https:\/\/cybersecuritynews.com\/hacker-arrested-for-stealing-spanish-banks\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation (GDPR)<\/a>, organizations must report qualifying personal data breaches to the relevant supervisory authority without undue delay, typically within 72 hours of becoming aware of the incident.<\/p>\n<p class=\"wp-block-paragraph\">This breach highlighted the risks associated with relying solely on passwords for services that hold highly valuable personal information. At the time of the attack, 23andMe did not require multi-factor authentication for all users.<\/p>\n<p class=\"wp-block-paragraph\">Security investigators later discovered that the company also lacked sufficiently strong password protections, failed to implement enhanced checks for raw genetic data downloads, and did not have effective systems in place to detect and respond to threats targeting customer accounts.<\/p>\n<p class=\"wp-block-paragraph\">Mandatory multi-factor authentication could have significantly reduced the success of credential stuffing attacks. In these incidents, threat actors automate login attempts using username-password combinations<a href=\"https:\/\/cybersecuritynews.com\/ciro-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\"> stolen from unrelated breaches<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">If a reused password is involved, it may grant access even if the targeted company has not directly suffered a network compromise. The 23andMe case also illustrates how privacy-focused product features can increase the impact of a breach.<\/p>\n<p class=\"wp-block-paragraph\">A single compromised account may expose information about relatives or connections who did not have their own accounts directly accessed.<\/p>\n<p class=\"wp-block-paragraph\">Organizations that handle genetic, medical, financial, or identity data should therefore assess the potential \u201c<a href=\"https:\/\/cybersecuritynews.com\/security-issues-mcp-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">blast radius<\/a>\u201d of every account takeover scenario.<\/p>\n<p class=\"wp-block-paragraph\">Spain\u2019s fine follows similar action in the UK, where 23andMe was fined \u00a32.31 million for inadequate security controls protecting sensitive user data.<\/p>\n<p class=\"wp-block-paragraph\">For security teams, this enforcement action reinforces a clear message: high-risk data environments require phishing-resistant authentication, breached-password screening, anomaly detection, robust download controls, and rapid incident reporting.<\/p>\n<p class=\"wp-block-paragraph\">The consequences of inadequate identity security can extend far beyond a direct account compromise when interconnected user data is involved.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong><strong>The Privilege Paths Attackers See That You Don\u2019t: BeyondTrust Pathfinder Platform Does It for You -&gt;\u00a0<a href=\"https:\/\/www.beyondtrust.com\/products\/identity-security-insights\/assessment?utm_source=cybersecuritynews&amp;utm_medium=web&amp;utm_campaign=prospecting&amp;campid=701Vw00000aN1mhIAC\">Get Free Identity Security Assessment<\/a><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/spain-fines-23andme-behind-user-breach\/\">Spain Fines 23andMe \u20ac2.4 Million Over Security Failures Behind 6.9 Million-User Breach<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/spain-fines-23andme-behind-user-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Spain Fines 23andMe \u20ac2.4 Million Over Security Failures Behind 6.9 Million-User Breach Spain\u2019s data protection authority has fined the genetic testing company 23andMe \u20ac2.4 million due to security failures linked to a data breach in 2023. This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-14484","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14484"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14484"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14484\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}