
Spain’s data protection authority has fined 23andMe €2.4 million over a 2023 security incident that compromised the personal data of approximately 2,600 Spanish residents.
In October 2023, 23andMe suffered a significant data breach where a hacker accessed sensitive health data by exploiting stolen usernames and passwords. The attacker used 23andMe’s DNA Relatives and Family Tree features to view additional information about account holders’ relatives. Some of the stolen data, including details on users of Ashkenazi and Chinese heritage, was posted on the dark web, further escalating concerns over the privacy of genetic information.
While the breach directly affected only a limited portion of 23andMe’s total accounts, the company confirmed that the personal data of 6.4 million users in the U.S. was compromised.
The breach triggered regulatory investigations and penalties, including a £2.31 million fine from the UK’s Information Commissioner’s Office (ICO). The watchdog found that 23andMe had failed to implement adequate safeguards to protect sensitive user data before the incident occurred.
Recently, the Spanish data protection regulator, the Agencia Española de Protección de Datos (AEPD), announced a €2.4 million fine against 23andMe after the data breach exposed the sensitive personal information of more than 2,600 Spanish residents.
According to the notice, 23andMe notified Spanish authorities about the cyber attack 12 days after becoming aware of the incident. The regulator stated that prompt notification was essential for effective mitigation efforts and described the delay as significant given the potential impact of the breach.
The regulator also found that 23andMe’s cyber security practices and safeguards for protecting highly sensitive genetic information were insufficient under GDPR requirements. It identified the absence of mandatory multi-factor authentication as a major factor that enabled the credential-stuffing attack and noted that the company lacked controls to limit data access, requests, or downloads based on IP address activity.
Earlier this month, New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement with 23andMe over allegations that the company failed to protect customers’ sensitive genetic information.
“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe puts millions of its customers at risk with its flimsy security measures.
“New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law and strict rules will be put in place to protect their customers,” Attorney General James said.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543