CSIDB logo
Incident

23andMe

Incident posture

Attack window
Apr 2023
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2026-07-23 13:23

Linked entities

Victim
23andMe
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

23andMe was fined three million dollars by Spain’s data protection authority after a credential‑stuffing breach exposed genetic data of about 6.9 million users, including over 2,600 Spaniards. The firm learned of the incident when a sample of the stolen data appeared for sale on Reddit, yet delayed notifying Spanish regulators for twelve days. Investigators cited missing multifactor authentication, no per‑IP access limits, and weak password policies as GDPR violations. Separately, the firm settled with forty‑two state attorneys general for eighteen million dollars, agreeing to strengthen safeguards at its research institute.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In April 2023, 23andMe experienced a data breach that came to light when an individual attempted to sell a sample of the compromised data on Reddit. The company's executives became aware of the breach after seeing the Reddit post. Despite learning of the incident, 23andMe did not notify Spanish data protection authorities until twelve days later. The Agencia Española de Protección de Datos (AEPD) later determined that the delay violated breach notification requirements under the General Data Protection Regulation.

The AEPD's decision cited multiple cybersecurity shortcomings that facilitated the breach, including the absence of mandatory multifactor authentication for user accounts, which was identified as a major factor in the credential stuffing attack. Additionally, the company did not impose limits on the number of data access requests, downloads, or queries that could originate from a single IP address. Its privacy policy contained only a single reference to account access credentials and did not specify any password strength requirements or mandatory periodic password changes. These deficiencies meant that 23andMe's safeguards for highly sensitive genetic data did not meet GDPR standards.

The breach affected approximately 6.9 million individuals worldwide, with more than 2,600 of those affected residing in Spain. As a result of the findings, the AEPD levied a fine of €2.4 million, equivalent to about $2.7 million, against the company. Separately, on July 15, 23andMe reached a settlement with a coalition of forty‑two state attorneys general, agreeing to pay eighteen million dollars and to implement new data protection measures at its 23andMe Research Institute, a nonprofit spinoff led by former CEO Anne Wojcicki.

Sources

Sources available to members: 1 source.

CSIDB