Data Breaches

Spain and the UK Fine 23andMe Over Genetic Data Breach Affecting 6.9 Million Users

Spain and the UK Fine 23andMe Over Genetic Data Breach Affecting 6.9 Million Users

Two regulators have now fined 23andMe for the same breach. Spain’s data protection authority issued a fine of nearly $3 million according to The Record from Recorded Future News. The UK’s Information Commissioner’s Office followed with a £2.31 million penalty confirmed in the ICO’s own press release published in June 2025. Both decisions stem from a credential stuffing attack that ran from April to September 2023 and exposed the personal and genetic data of 6.9 million users worldwide.

23andMe became aware of the intrusion in August 2023 meaning attackers had been inside for roughly four months before the company detected anything. By the time it was over, compromised records included names, home addresses and genetic ancestry data. For most data breaches, leaked contact details are the primary concern. Genetic information is different. It does not expire, cannot be reset and carries implications not just for the individual but for their biological relatives who never consented to anything.

A Credential Stuffing Attack That Should Have Been Stopped

Credential stuffing is not a sophisticated technique. Attackers take username and password combinations leaked in previous, unrelated breaches and attempt them at scale against a target service. It works because a significant share of users reuse passwords across accounts. The defence is equally straightforward, require multi-factor authentication, monitor login patterns for anomalies and treat multiple failed attempts across different accounts as an alert condition, not background noise.

23andMe did not require MFA by default at the time of the attack. The ICO’s finding, as reported by The Record and confirmed in the ICO’s own notice, was that the company failed to implement adequate security measures to protect data of particular sensitivity. Genetic data sits in a special category under GDPR and UK data protection law, attracting stronger obligations precisely because of the harm its exposure causes. The ICO’s position is that 23andMe knew it held this category of data and did not apply the controls that classification demands.

The attackers did not need a zero-day. They needed a list of recycled passwords and enough time. They had five months.

The Fines Signal a Harder Line on Genetic Data

The Spanish fine of nearly $3 million comes from the Agencia Española de Protección de Datos, reported by The Record. The ICO’s £2.31 million fine is documented in the regulator’s own published decision. Together they represent parallel enforcement actions across two jurisdictions against the same underlying failure, a company handling some of the most sensitive personal data in existence did not apply security controls commensurate with that responsibility.

The ICO’s fine is notable for what it signals about regulator appetite. The ICO has historically been criticised for issuing guidance rather than penalties. A seven-figure fine against a foreign genomics company for a breach of UK users’ genetic data suggests the posture is shifting. Spain’s action, issued independently and at a comparable scale, reinforces that reading.

Neither fine is existential for a company of 23andMe’s former scale but 23andMe filed for bankruptcy protection in the United States in March 2025, according to Wikipedia’s documentation of the company’s history. The regulatory penalties arrive as the company attempts to sell its assets which include the genetic profiles of millions of customers. Who buys those profiles and under what data protection obligations, is a question that neither the ICO nor the AEPD has publicly resolved.

What Any Organisation Holding Biometric or Genetic Data Should Do Before Its Next Audit

The 23andMe case is an instruction manual for what not to do. Three actions apply directly to any organisation holding special category data under GDPR or UK data protection law.

  • Enforce MFA on every account with access to special category data. Not as an option users can enable. As a mandatory control. The ICO’s decision makes clear that offering MFA as a voluntary feature does not satisfy the obligation to implement adequate security measures when the underlying data warrants stronger protection.
  • Monitor for credential stuffing patterns. Automated login attempts using valid credentials from external breach lists look different from normal user behaviour. Volume thresholds, geographic anomalies and device fingerprinting all generate signals. Those signals are only useful if someone is watching for them.
  • Audit what you actually hold before a regulator asks. Organisations routinely underestimate the sensitivity of their data estate. If your user records include health indicators, ancestry information or any biometric identifier, those records attract special category obligations regardless of whether your core product is marketed as a health service.

The ICO’s full decision is published at ico.org.uk and is worth reading in detail for any data protection officer managing health or genomic data. The Spanish AEPD decision is covered in The Record’s reporting linked below.

References

  1. Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 hHack
  2. UK Data Privacy Regulator Fines 23andMe Over Cyber Practices in Wake of Hack
  3. ICO: 23andMe Fined £2.31 Million for Failing to Protect UK Users’ Genetic Data
  4. 23andMe Data Leak
  5. UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.