Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
Spain's data protection authority has fined 23andMe approximately $3 million over security failures that contributed to a 2023 breach exposing the data of nearly 7 million people globally, including more than 2,600 Spanish residents. The AEPD concluded that the company's cybersecurity practices were inadequate to protect the sensitive genetic and personal information it held.
Why this matters: Genetic data is not like a leaked password. You cannot change your DNA. When a company holding that kind of information gets breached because of its own security failures, the people affected carry that exposure for life. Spain's fine puts a concrete price on getting this wrong. What matters now is whether 23andMe — a company already in serious financial trouble — can actually make anyone whole, or whether the people whose data was taken are simply left with the risk.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.