Spain’s national data protection authority has fined 23andMe €2.4 million, approximately $2.7 million, after determining that the genetic-testing company failed to provide adequate security for highly sensitive customer information and waited beyond the required deadline to report its 2023 data breach.
The Agencia Española de Protección de Datos, known as the AEPD, found that the breach exposed personal information belonging to 2,642 people living in Spain. The affected records included identity information, contact and location details, images, health information, genetic data, and information revealing ethnic origin.
The Spanish enforcement action is connected to the broader 23andMe breach that affected approximately 6.9 million customers worldwide. Some of the compromised data was later advertised or published through internet forums and dark-web markets.
The AEPD divided the €2.4 million penalty between two separate violations of the European Union’s General Data Protection Regulation. The authority imposed a €2 million fine for failing to maintain appropriate security and confidentiality protections and an additional €400,000 fine for failing to report the breach within the period required under European law.
The breach resulted from a credential-stuffing attack in which cybercriminals used usernames and passwords exposed through earlier incidents involving other services. The attackers tested those credentials against 23andMe accounts, gaining access when customers had reused the same login information.
Credential stuffing does not require an attacker to break a company’s encryption or discover a new software vulnerability. It relies on automated login attempts using credentials already stolen elsewhere. The attack method is widely known, making defenses such as mandatory multifactor authentication, breached-password screening, rate limiting, abnormal-login detection, and restrictions on large data requests central to preventing widespread account access.
At the time of the attack, 23andMe allowed customers to activate multifactor authentication but did not require it. Customers could access accounts containing genetic and health information using only a username and password.
The Spanish regulator also found that 23andMe had not established limits on the amount of data that could be accessed, requested, or downloaded through a single internet address. That absence allowed compromised accounts and connected family information to be accessed without sufficient restrictions capable of slowing or stopping the activity.
The company’s DNA Relatives feature expanded the consequences. Access to one compromised account could reveal information connected to other customers identified as possible biological relatives, allowing the breach to reach people whose own passwords had not been compromised.
According to the AEPD’s findings, 23andMe detected a Reddit message on October 1, 2023, offering information that was purportedly taken from its customers. The company confirmed by October 5 that part of the published information belonged to one of its customers.
23andMe posted a security notice on its website on October 6 and notified authorities in the United States on October 7. It emailed customers about the incident on October 10.
The company identified 799 affected Spanish customers by October 12 and notified those individuals on October 13. It did not report the breach to the Spanish authority until October 17, 12 days after confirming that the published information belonged to a customer and 16 days after detecting the Reddit sale offer.
The company later identified another 1,843 affected people in Spain and notified them on October 24. It provided the AEPD with expanded information on October 30, bringing the confirmed Spanish total to 2,642.
Article 33 of the GDPR generally requires an organization to notify the appropriate supervisory authority without undue delay and, when possible, within 72 hours of becoming aware of a personal-data breach that may create risks for individuals. A delayed notification must include the reasons for the delay.
The AEPD rejected any suggestion that timely reporting was a minor procedural requirement. Early notification allows regulators to assess risks, coordinate protective measures, and determine whether affected people need additional warnings before stolen information is exploited.
The regulator found that a sample of the compromised information had been published on an internet forum and that a file containing customer data had been placed for sale on the dark web.
Unlike a password or payment-card number, genetic data cannot be canceled and replaced after a breach. It can reveal ancestry, biological relationships, health-related characteristics, and inherited traits. Genetic information can also expose details about relatives who never submitted their own samples to the affected company.
The AEPD classified the exposed genetic, health, and ethnic-origin information as particularly sensitive data carrying a high risk to the rights and freedoms of the affected customers.
The regulator also examined 23andMe’s privacy policy, which said customers were responsible for safeguarding their passwords and authentication information. The authority found that the policy did not establish specific password-strength requirements or require customers to periodically change their passwords.
Placing responsibility on users did not remove the company’s obligation to deploy technical and organizational safeguards proportionate to the sensitivity of the information it collected and stored.
The AEPD also reviewed 23andMe’s fiscal 2023 annual report, signed in May 2023 by company leadership. In that report, 23andMe acknowledged that global cybersecurity threats and targeted cybercrime could endanger its systems, networks, and the confidentiality, availability, and integrity of its data.
The report also acknowledged that a security or privacy incident could force the company to comply with breach-notification requirements, pay remediation expenses, face penalties, conduct security audits or forensic investigations, replace affected systems, and take steps to prevent future incidents.
Those disclosures showed that 23andMe understood the financial, regulatory, and operational dangers associated with cyberattacks before the breach was discovered.
The Spanish authority also addressed the reach of European privacy law. Although 23andMe was based in the United States and did not have a principal establishment in the European Union, the company offered genetic-testing and analysis services to people living in Spain and other European countries.
The GDPR applies to certain organizations outside the European Union when they offer goods or services to people inside the region or monitor their behavior. A company does not avoid European data-protection requirements solely because its headquarters and computer systems are located elsewhere.
The AEPD determined that 23andMe’s business depended heavily on processing especially sensitive personal information. That relationship between the company’s core services and the exposed data was considered an aggravating factor when the regulator calculated the penalty.
23andMe reported 2023 revenue of approximately $299.5 million, equivalent to roughly €263 million at the conversion used in the Spanish proceeding.
The €2.4 million decision ends the administrative proceeding before the AEPD, but 23andMe retains the right to seek administrative reconsideration within one month or challenge the decision before Spain’s National Court within two months. The penalty becomes enforceable after the applicable appeal period expires if the company does not pursue those options.
The decision requires publication of information identifying the company, the violations, and the penalty because the total sanction exceeds €1 million.
The Spanish enforcement action follows extensive legal and financial consequences in the United States. In March 2025, 23andMe entered bankruptcy protection, and state attorneys general filed claims connected to the 2023 breach.
A multistate coalition reached an $18 million settlement resolving government claims arising from the breach. The bankruptcy settlement recognized $150 million in state claims, but the amount available for immediate recovery was limited to $18 million because of the funds remaining in the bankruptcy estate and the number of competing claims.
A separate $46.75 million class-action settlement was approved within the bankruptcy process to provide relief to eligible U.S. consumers who submitted claims by the established February 17, 2026, deadline.
23andMe’s assets, including customer data, were sold during bankruptcy proceedings to TTAM Research Institute, a nonprofit organization formed by 23andMe founder and former chief executive Anne Wojcicki. The organization was later registered as the 23andMe Research Institute.
The terms governing the transfer included stronger information-security requirements, formal risk assessments, an advisory board focused on data security, continued compliance with privacy laws, and preservation of customers’ ability to request deletion of their information.
State investigators identified many of the same security weaknesses documented by the Spanish authority. Those findings included the failure to require multifactor authentication, insufficient protection against credential stuffing, inadequate rate limiting, limited logging and monitoring, failure to respond properly to unusual login patterns, unresolved vulnerabilities, and inadequate testing of product features that expanded access to other customers’ data.
The Spanish penalty reinforces a central responsibility for every organization handling genetic information: the sensitivity of the data must determine the strength of the protection surrounding it.
23andMe collected information that cannot be replaced after exposure and may reveal personal details extending across biological families. The AEPD concluded that voluntary multifactor authentication, unrestricted data requests, weak access controls, and delayed regulatory notification did not satisfy the protections required for information of that magnitude and permanence.
The €2.4 million sanction does not reverse the breach or remove the exposed genetic information from criminal possession. It establishes that companies collecting DNA, health information, and ancestry records remain responsible for anticipating known attack methods and placing enforceable security barriers between stolen credentials and their customers’ most permanent personal data.
Agencia Española de Protección de Datos, Resolution of Sanctioning Procedure PS/00140/2025, Case No. EXP202316010, concerning the 2023 23andMe data breach and the €2.4 million administrative penalty. (Free Download)
United States Bankruptcy Court for the Eastern District of Missouri, In re: Chrome Holding Co., formerly known as 23andMe Holding Co., Case No. 25-40976-357, Plan Administration Trust’s motion seeking approval of the agreement resolving claims connected to the 2023 cybersecurity incident. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



