Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
Spain has fined 23andMe €2.4 million ($2.7 million) for failing to notify Spanish authorities about a 2023 data breach that impacted over 6.9 million people worldwide. The regulator cited inadequate cybersecurity practices, including a lack of multifactor authentication and insufficient IP address restrictions, leading to a breach that was initially discovered when data was offered for sale on Reddit. This follows a separate $18 million settlement with 42 state attorneys general.
Spain has fined 23andMe €2.4 million ($2.7 million) for cybersecurity failings that enabled a 2023 data breach. The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, stating that more than 2,600 Spaniards were affected by the breach, impacting a total of 6.9 million people globally. The regulator determined that 23andMe’s cybersecurity practices did not meet General Data Protection Regulation (GDPR) requirements, specifically highlighting a lack of mandatory multifactor authentication and insufficient IP address restrictions, which allowed a credential stuffing attack to succeed.
The breach was initially discovered when a sample of the hacked data was offered for sale on Reddit. 23andMe did not notify Spanish officials about the hack until 12 days after the firm learned of it, despite the regulator deeming the need for immediate notification “not trivial” due to the importance of early mitigation.
23andMe’s privacy policy only includes one reference to account access credentials and does not “indicate any specific requirements regarding the password format in relation to its strength, nor any requirement to modify it periodically.” The AEPD also noted that 23andMe cited ransomware and other cyber threats in a May 2023 fiscal report, which the regulator found on the firm’s website.
This incident follows a $18 million settlement with 42 state attorneys general in July, where 23andMe pledged to implement new data protection measures at 23andMe Research Institute. The AEPD’s decision underscores the importance of robust cybersecurity practices and timely notification of data breaches, particularly when dealing with sensitive personal data like genetic information.
