Therecord.Media Spain Fines 23andMe €2.4 Million for 2023 Data Breach
Article Content
- •23andMe fined €2.4 million for a 2023 data breach affecting 6.9 million users globally.
- •The breach exposed sensitive data of over 2,600 Spaniards due to a credential-stuffing attack.
- •The fine was announced by Spain's data protection authority, AEPD, on July 21, 2026.
Spain's data protection authority has imposed a €2.4 million fine on 23andMe due to security failures that led to a data breach in 2023. The breach exposed sensitive genetic, health, and family-related information of over 2,600 individuals in Spain, part of a larger incident affecting 6.9 million users globally. The breach was attributed to a credential-stuffing attack, which allowed unauthorized access to user accounts. The fine was announced by the Agencia Española de Protección de Datos (AEPD) on July 21, 2026, highlighting the serious implications of inadequate cybersecurity measures. This incident emphasizes the need for robust security protocols in handling sensitive personal data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track 23andMe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…