23andme
Image: tsd studio via Unsplash

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Executives at 23andMe learned about the company's April 2023 data breach after someone tried to sell a sample of the hacked data on Reddit, according to an enforcement decision connected with a €2.4 million ($2.7 million) fine levied by a Spanish data privacy regulator.

The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide. 

23andMe didn’t notify Spanish officials about the hack until 12 days after the firm learned of it, according to the decision, which called the need for immediate notification “not trivial” due to the importance of early mitigation.

The firm’s poor cybersecurity practices and lack of appropriate safeguards for highly sensitive genetic data did not meet General Data Protection Regulation (GDPR) requirements, the decision said, citing 23andMe’s lack of mandatory multifactor authentication as a major factor in the credential stuffing attack.

The firm also did not place limits on accessing, requesting or downloading data per IP address, the decision said.

The cybersecurity failings are particularly striking because 23andMe cited ransomware and other cyber threats at length in a May 2023 fiscal report the regulator found on the firm’s website.

“The rise in global cybersecurity threats and more sophisticated and targeted cybercrime poses a risk to the security of our systems and networks, as well as the confidentiality, availability, and integrity of our data,” the fiscal report said, according to the Spanish decision.

A security or privacy breach leading to exposure of customer data could require 23andMe to “comply with breach notification laws and cause us to incur significant costs for remediation… and to prevent future occurrences, potential increases in insurance premiums, and security audits or forensic investigations,” 23andMe said in the fiscal report.

23andMe’s privacy policy only includes one reference to account access credentials and does not “indicate any specific requirements regarding the password format in relation to its strength, nor any requirement to modify it periodically,” the regulator’s decision noted.

On July 15, 23andMe settled with a coalition of 42 state attorneys general for $18 million, pledging to implement new data protection measures at 23andMe Research Institute, a nonprofit spinoff of the firm that is helmed by former company CEO Anne Wojcicki.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Suzanne Smalley

Suzanne Smalley

is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.