23andMe Data Breach: Spain Fines Firm €2.4 Million

The 23andMe data breach has resulted in Spain’s data protection authority levying a €2.4 million fine against the genetic testing company. This high-profile security incident, which emerged in 2023, exposed data associated with 6.9 million users and highlighted critical weaknesses in 23andMe’s account security and breach response.

Details of the 23andMe Credential-Stuffing Breach

The breach that prompted the fine occurred in 2023, when attackers successfully carried out a credential-stuffing attack targeting 23andMe’s user accounts. Credential stuffing involves using login credentials (often sourced from other, unrelated breaches) to gain unauthorised access to accounts on a different platform. In this case, the attackers exploited users’ tendency to reuse passwords across multiple services.

According to the findings of the Spanish authority, the initial compromise affected around 14,000 23andMe accounts. However, the design of 23andMe’s platform enabled the attackers to leverage social and DNA-relative features to access information connected to a much larger group of users. Ultimately, data linked to approximately 6.9 million global users was exposed, including highly sensitive genetic, health, ethnicity and family-related information. In Spain alone, more than 2,600 individuals were directly impacted.

  • Attack method: Credential stuffing using passwords leaked from other breaches
  • Accounts directly accessed: ~14,000
  • Broader user impact: Up to 6.9 million profiles worldwide
  • Data exposed: Genetic data, health information, ethnicity, family connections
  • Timeline: Breach occurred in 2023, investigation and fine issued in 2024

Security Failures Identified by Spanish Regulators

The Spanish Data Protection Authority (AEPD) conducted a detailed investigation and found multiple shortcomings in 23andMe’s security and incident response practices. Central to their findings was the absence of mandatory multi-factor authentication (MFA), which would have provided a critical barrier against automated credential-stuffing attacks. At the time of the breach, 23andMe did not require MFA for all users, a significant gap given the sensitivity of the data held.

Further, the authority highlighted the following security failures:

  • Weak password protections: Insufficient password strength requirements and inadequate monitoring for unusual login patterns.
  • Insufficient monitoring of account activity: Lack of robust controls to detect and respond to suspicious login behaviour or bulk data downloads.
  • Poor controls on genetic data downloads: Absence of enhanced checks or restrictions for users seeking to download raw genetic data.
  • Late breach notification: 23andMe did not notify authorities within the GDPR’s 72-hour requirement after becoming aware of the incident.

The combination of these deficiencies created an environment where attackers could not only access individual accounts but also exploit the interconnected nature of 23andMe’s DNA-relative features. This design allowed the blast radius of the breach to extend far beyond the initial compromised accounts, exposing vast amounts of sensitive data about individuals who were not directly targeted.

Timeline and Regulatory Actions

The breach was discovered and reported in 2023, but regulatory scrutiny continued into 2024. The Spanish AEPD issued its €2.4 million fine after reviewing the nature and impact of the breach, the company’s security posture, and its compliance with GDPR obligations. The fine specifically addresses the inadequate level of security controls and the delayed incident reporting. Notably, Spain’s action follows a similar penalty by UK data protection authorities, who fined 23andMe £2.31 million for related failings.

The key milestones in the breach timeline are as follows:

  • 2023: Credential-stuffing attack occurs, exposing 6.9 million users’ data globally
  • 2023: 23andMe detects the breach and launches an internal investigation
  • 2023: Company notifies regulators, but after the GDPR’s 72-hour reporting window
  • 2024: Spanish AEPD issues €2.4 million fine for inadequate security and delayed notification
  • 2024: UK regulator levies a similar fine for security failings

At the time of writing, there is no evidence that the attackers exploited a vulnerability in 23andMe’s technical infrastructure. Instead, the breach relied entirely on user credential reuse and the absence of additional authentication steps, such as MFA. Security researchers did not identify indicators of ongoing exploitation beyond the initial attack, but the scope of the data exposed means long-term privacy risks remain for affected individuals.

Why This Breach Matters for Organisations

This incident underscores the heightened obligations for organisations that handle highly sensitive personal data, such as genetic or health information. The 23andMe breach demonstrates how product features that encourage connectivity or data sharing can inadvertently increase the impact of account takeovers. It also highlights the regulatory expectation that companies will proactively enforce security measures like MFA and respond rapidly to incidents to minimise harm.

Actionable Steps Following the 23andMe Data Breach

Organisations, especially those processing sensitive data, should draw lessons from this event:

  • Mandate multi-factor authentication for all users to disrupt credential-stuffing attempts.
  • Assess and restrict features that could amplify the reach of an account compromise.
  • Review and enhance breach detection and notification procedures to comply with GDPR timelines.
  • Monitor for unusual account activity and bulk data downloads to catch suspicious behaviour early.

Implementing these targeted measures can significantly lower the risk of similar breaches and regulatory fines.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call