23andMe Fined €2.4M After Reddit Post Reveals Data Breach Impacting 6.9 Million
Genetic testing giant **23andMe** has been hit with a €2.4 million fine by a Spanish data privacy regulator following a data breach that exposed the sensitive genetic information of 6.9 million users worldwide. The breach, which **23andMe** reportedly discovered after a sample of the stolen data appeared on Reddit, highlighted significant cybersecurity failings, including a lack of mandatory multifactor authentication.
A recent enforcement decision by the **Agencia Española de Protección de Datos (AEPD)** has revealed critical insights into the **23andMe** data breach that impacted 6.9 million individuals globally. The Spanish regulator levied a €2.4 million ($2.7 million) fine against the genetic testing company, citing a lack of appropriate safeguards for highly sensitive genetic data and delayed breach notification.
### Breach Discovery and Delayed Notification
**23andMe** executives reportedly learned of the April 2023 data breach only after an attempt to sell a sample of the hacked data surfaced on Reddit. Despite this, the company failed to notify Spanish officials until 12 days after the discovery, a delay the **AEPD** deemed “not trivial” given the importance of early mitigation.
### Cybersecurity Failings Under Scrutiny
The **AEPD**'s decision highlighted several critical cybersecurity deficiencies at **23andMe**, which it found to be in breach of **General Data Protection Regulation (GDPR)** requirements. A major contributing factor to the credential stuffing attack was the absence of mandatory multifactor authentication (MFA) for user accounts. Furthermore, the company reportedly lacked controls to limit data access, requests, or downloads per IP address.
These failings are particularly concerning as **23andMe** itself acknowledged the growing threat landscape in a May 2023 fiscal report. The report explicitly mentioned the risks posed by “the rise in global cybersecurity threats and more sophisticated and targeted cybercrime” to the security and integrity of its data.
The regulator also noted that **23andMe**'s privacy policy offered only a single reference to account access credentials and provided no specific requirements for password strength or periodic modification.
### Settlement and Future Measures
In related news, **23andMe** recently reached an $18 million settlement with a coalition of 42 state attorneys general on July 15. As part of this agreement, the company has pledged to implement new data protection measures at the **23andMe Research Institute**, a nonprofit spinoff led by former CEO **Anne Wojcicki**.