Decoding the world of cybersecurity

Genetic data failures cost 23andMe €2.4m

Spain’s privacy regulator found that optional authentication, unrestricted data access, and delayed notification failed to protect highly sensitive genetic information.

Genetic data failures cost 23andMe €2.4m
Summary
  • The AEPD found that data belonging to 2,642 Spanish residents had been exposed.
  • Multifactor authentication was optional, while access and downloads were not adequately restricted by source address.
  • Credential stuffing did not remove 23andMe’s responsibility to protect genetic and health information.

Spain’s data protection authority has fined 23andMe €2.4 million after finding that its security and incident-notification practices failed to protect genetic and health information during the company’s 2023 breach.

The Agencia Española de Protección de Datos, or AEPD, identified 2,642 affected people in Spain. Exposed information included identity and contact details, location data, images, health information, genetic data, and ethnicity. A sample was published online, while a larger file was offered for sale on a criminal forum.

The attackers used credential stuffing, testing usernames and passwords obtained from unrelated breaches against 23andMe accounts. Once an account was accessed, connected features could expose information relating to the account holder and genetic relatives who had chosen to participate in ancestry and matching services.

Multifactor authentication was available but not mandatory when the attack occurred. The regulator also found that the service did not apply adequate limits to the volume of information that could be accessed, requested, or downloaded from a single source address. A relatively small number of reused credentials was therefore capable of producing a much larger exposure.

The AEPD imposed €2 million for breaching the General Data Protection Regulation’s integrity and confidentiality requirements and a further €400,000 for failing to meet the breach-notification obligation. Its enforcement decision records that notification did not occur within the expected 72-hour period after the company had sufficient knowledge of the incident.

Credential stuffing begins with passwords exposed elsewhere, although the controller remains responsible for the way its own service responds when those credentials are accepted. GDPR requires measures proportionate to the risk, and genetic information carries consequences that cannot be reversed by resetting a password or replacing an account number.

Genetic data is persistent, reveals biological relationships, and can expose information about people who never created an account with the breached service. It may also intersect with health, ancestry, ethnicity, and family information, raising the expected standard for authentication, anomaly detection, data minimisation, and control of large-scale exports.

Product design also influenced the scale of the incident. A compromised account becomes more damaging when it can query connected profiles or retrieve significant quantities of data without step-up verification or effective rate limits. A successful login cannot be treated as sufficient evidence that every subsequent request is legitimate.

Regulatory action has not been confined to Spain. The UK Information Commissioner’s Office fined 23andMe £2.31 million in 2025 over failures affecting 155,592 UK residents. The ICO found that additional verification for access to raw genetic data was introduced too late and that the company’s response did not meet the required standard.

The Spanish decision adds to a cross-border enforcement record built around the same underlying breach. Organisations holding health, biometric, genomic, or similarly durable information need controls that reflect the harm likely to follow account compromise rather than the apparent simplicity of the initial technique.

Mandatory multifactor authentication, behavioural detection, rate limits, step-up verification for sensitive exports, and tested notification procedures perform different functions. Together, they reduce the chance that one reused password can expose information whose sensitivity extends beyond the account holder and beyond the lifetime of the service.

The AEPD’s decision remains subject to the applicable appeal process. Its findings place responsibility on the service’s authentication and access design, rather than allowing the origin of the reused passwords to define the limits of 23andMe’s obligations.

×