The 23andMe data breach has resulted in Spain’s data protection authority levying a €2.4 million fine against the genetic testing company. This high-profile security incident, which emerged in 2023, exposed data associated with 6.9 million users and highlighted critical weaknesses in 23andMe’s account security and breach response.
Details of the 23andMe Credential-Stuffing Breach
The breach that prompted the fine occurred in 2023, when attackers successfully carried out a credential-stuffing attack targeting 23andMe’s user accounts. Credential stuffing involves using login credentials (often sourced from other, unrelated breaches) to gain unauthorised access to accounts on a different platform. In this case, the attackers exploited users’ tendency to reuse passwords across multiple services.
According to the findings of the Spanish authority, the initial compromise affected around 14,000 23andMe accounts. However, the design of 23andMe’s platform enabled the attackers to leverage social and DNA-relative features to access information connected to a much larger group of users. Ultimately, data linked to approximately 6.9 million global users was exposed, including highly sensitive genetic, health, ethnicity and family-related information. In Spain alone, more than 2,600 individuals were directly impacted.
- Attack method: Credential stuffing using passwords leaked from other breaches
- Accounts directly accessed: ~14,000
- Broader user impact: Up to 6.9 million profiles worldwide
- Data exposed: Genetic data, health information, ethnicity, family connections
- Timeline: Breach occurred in 2023, investigation and fine issued in 2024
Security Failures Identified by Spanish Regulators
The Spanish Data Protection Authority (AEPD) conducted a detailed investigation and found multiple shortcomings in 23andMe’s security and incident response practices. Central to their findings was the absence of mandatory multi-factor authentication (MFA), which would have provided a critical barrier against automated credential-stuffing attacks. At the time of the breach, 23andMe did not require MFA for all users, a significant gap given the sensitivity of the data held.
Further, the authority highlighted the following security failures:
- Weak password protections: Insufficient password strength requirements and inadequate monitoring for unusual login patterns.
- Insufficient monitoring of account activity: Lack of robust controls to detect and respond to suspicious login behaviour or bulk data downloads.
- Poor controls on genetic data downloads: Absence of enhanced checks or restrictions for users seeking to download raw genetic data.
- Late breach notification: 23andMe did not notify authorities within the GDPR’s 72-hour requirement after becoming aware of the incident.
The combination of these deficiencies created an environment where attackers could not only access individual accounts but also exploit the interconnected nature of 23andMe’s DNA-relative features. This design allowed the blast radius of the breach to extend far beyond the initial compromised accounts, exposing vast amounts of sensitive data about individuals who were not directly targeted.
Timeline and Regulatory Actions
The breach was discovered and reported in 2023, but regulatory scrutiny continued into 2024. The Spanish AEPD issued its €2.4 million fine after reviewing the nature and impact of the breach, the company’s security posture, and its compliance with GDPR obligations. The fine specifically addresses the inadequate level of security controls and the delayed incident reporting. Notably, Spain’s action follows a similar penalty by UK data protection authorities, who fined 23andMe £2.31 million for related failings.
The key milestones in the breach timeline are as follows:
- 2023: Credential-stuffing attack occurs, exposing 6.9 million users’ data globally
- 2023: 23andMe detects the breach and launches an internal investigation
- 2023: Company notifies regulators, but after the GDPR’s 72-hour reporting window
- 2024: Spanish AEPD issues €2.4 million fine for inadequate security and delayed notification
- 2024: UK regulator levies a similar fine for security failings
At the time of writing, there is no evidence that the attackers exploited a vulnerability in 23andMe’s technical infrastructure. Instead, the breach relied entirely on user credential reuse and the absence of additional authentication steps, such as MFA. Security researchers did not identify indicators of ongoing exploitation beyond the initial attack, but the scope of the data exposed means long-term privacy risks remain for affected individuals.
Why This Breach Matters for Organisations
This incident underscores the heightened obligations for organisations that handle highly sensitive personal data, such as genetic or health information. The 23andMe breach demonstrates how product features that encourage connectivity or data sharing can inadvertently increase the impact of account takeovers. It also highlights the regulatory expectation that companies will proactively enforce security measures like MFA and respond rapidly to incidents to minimise harm.
Actionable Steps Following the 23andMe Data Breach
Organisations, especially those processing sensitive data, should draw lessons from this event:
- Mandate multi-factor authentication for all users to disrupt credential-stuffing attempts.
- Assess and restrict features that could amplify the reach of an account compromise.
- Review and enhance breach detection and notification procedures to comply with GDPR timelines.
- Monitor for unusual account activity and bulk data downloads to catch suspicious behaviour early.
Implementing these targeted measures can significantly lower the risk of similar breaches and regulatory fines.
Originally reported by cybersecuritynews.com.




