BTC$63,083+0.50% LTC$44.11+1.19% XMR$409.26+2.83%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Jul 21, 2026 · 2 min read · Original story

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Executives at 23andMe learned about the company's April 2023 data breach after someone tried to sell a sample of the hacked data on Reddit, according to an enforcement decision connected with a €2.4 million ($2.7 million) fine levied by a Spanish data privacy regulator.

The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.

23andMe didn’t notify Spanish officials about the hack until 12 days after the firm learned of it, according to the decision, which called the need for immediate notification “not trivial” due to the importance of early mitigation.

The firm’s poor cybersecurity practices and lack of appropriate safeguards for highly sensitive genetic data did not meet General Data Protection Regulation (GDPR) requirements, the decision said, citing 23andMe’s lack of mandatory multifactor authentication as a major factor in the credential stuffing attack.

The firm also did not place limits on accessing, requesting or downloading data per IP address, the decision said.

The cybersecurity failings are particularly striking because 23andMe cited ransomware and other cyber threats at length in a May 2023 fiscal report the regulator found on the firm’s website.

“The rise in global cybersecurity threats and more sophisticated and targeted cybercrime poses a risk to the security of our systems and networks, as well as the confidentiality, availability, and integrity of our data,” the fiscal report said, according to the Spanish decision.

A security or privacy breach leading to exposure of customer data could require 23andMe to “comply with breach notification laws and cause us to incur significant costs for remediation… and to prevent future occurrences, potential increases in insurance premiums, and security audits or forensic investigations,” 23andMe said in the fiscal report.

23andMe’s privacy policy only includes one reference to account access credentials and does not “indicate any specific requirements regarding the password format in relation to its strength, nor any requirement to modify it periodically,” the regulator’s decision noted.

On July 15, 23andMe settled with a coalition of 42 state attorneys general for $18 million, pledging to implement new data protection measures at 23andMe Research Institute, a nonprofit spinoff of the firm that is helmed by former company CEO Anne Wojcicki.

References in this story

  1. 23andMe reaches $18 million settlement with states for massive breach therecord.media A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.
  2. Nonprofit led by 23andMe’s former CEO wins bid to acquire the company therecord.media TTAM Research Institute, led by former 23andMe chief executive Anne Wojcicki, is waiting for a judge to approve its acquisition of the company.
  3. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
  4. Suzanne Smalley (@suzannesmalley.bsky.social) bsky.app Reporter covering digital privacy and cybersecurity policy for The Record. Mom. Pub trivia queen. Crossword enthusiast. Literary fiction connoisseur. Idiosyncratic. Signal: Suzanne.236 Email…

Guides related to this story

← Back to all news