Cyber Incident Victim: 23andMe
Date:
Apr 2023
Location:
Spain
Summary
23andMe was fined three million dollars by Spain’s data protection authority after a credential‑stuffing breach exposed genetic data of about 6.9 million users, including over 2,600 Spaniards. The firm learned of the incident when a sample of the stolen data appeared for sale on Reddit, yet delayed notifying Spanish regulators for twelve days. Investigators cited missing multifactor authentication, no per‑IP access limits, and weak password policies as GDPR violations. Separately, the firm settled with forty‑two state attorneys general for eighteen million dollars, agreeing to strengthen safeguards at its research institute.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In April 2023, 23andMe experienced a data breach that came to light when an individual attempted to sell a sample of the compromised data on Reddit. The company's executives became aware of the breach after seeing the Reddit post. Despite learning of the incident, 23andMe did not notify Spanish data protection authorities until twelve days later. The Agencia Española de Protección de Datos (AEPD) later determined that the delay violated breach notification requirements under the General Data Protection Regulation.

The AEPD's decision cited multiple cybersecurity shortcomings that facilitated the breach, including the absence of mandatory multifactor authentication for user accounts, which was identified as a major factor in the credential stuffing attack. Additionally, the company did not impose limits on the number of data access requests, downloads, or queries that could originate from a single IP address. Its privacy policy contained only a single reference to account access credentials and did not specify any password strength requirements or mandatory periodic password changes. These deficiencies meant that 23andMe's safeguards for highly sensitive genetic data did not meet GDPR standards.
The breach affected approximately 6.9 million individuals worldwide, with more than 2,600 of those affected residing in Spain. As a result of the findings, the AEPD levied a fine of €2.4 million, equivalent to about $2.7 million, against the company. Separately, on July 15, 23andMe reached a settlement with a coalition of forty‑two state attorneys general, agreeing to pay eighteen million dollars and to implement new data protection measures at its 23andMe Research Institute, a nonprofit spinoff led by former CEO Anne Wojcicki.
