Spain Fines 23andMe €2.4 Million for 2023 Data Breach

Spain Fines 23andMe €2.4 Million for 2023 Data Breach

First seen 22 Jul 2026, 15:25 UTC Therecord.MediaCybersecuritynews 81% similarity 51.8

Article Content

Browse articles
ThreatCluster

Spain's data protection authority has imposed a €2.4 million fine on 23andMe due to security failures that led to a data breach in 2023. The breach exposed sensitive genetic, health, and family-related information of over 2,600 individuals in Spain, part of a larger incident affecting 6.9 million users globally. The breach was attributed to a credential-stuffing attack, which allowed unauthorized access to user accounts. The fine was announced by the Agencia Española de Protección de Datos (AEPD) on July 21, 2026, highlighting the serious implications of inadequate cybersecurity measures. This incident emphasizes the need for robust security protocols in handling sensitive personal data.

Key Points: • 23andMe fined €2.4 million for a 2023 data breach affecting 6.9 million users globally. • The breach exposed sensitive data of over 2,600 Spaniards due to a credential-stuffing attack. • The fine was announced by Spain's data protection authority, AEPD, on July 21, 2026.

ThreatCluster AI

Timeline

2023-01-15
Credential-stuffing attack on 23andMe
A credential-stuffing attack compromised user accounts, exposing sensitive data of millions.
Cybersecuritynews
2023-01-20
Data breach disclosed
23andMe publicly acknowledged the data breach affecting 6.9 million users worldwide.
Date unknown
2026-07-21
Spain announces fine against 23andMe
The AEPD imposed a €2.4 million fine for security failures linked to the 2023 breach.
Therecord.Media

Community

Browse all →