PrivacySignal
Breach

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

The Record · · International · Data Breaches

Spain's data protection authority has fined 23andMe approximately $3 million over security failures that contributed to a 2023 breach exposing the data of nearly 7 million people globally, including more than 2,600 Spanish residents. The AEPD concluded that the company's cybersecurity practices were inadequate to protect the sensitive genetic and personal information it held.

Why this matters: Genetic data is not like a leaked password. You cannot change your DNA. When a company holding that kind of information gets breached because of its own security failures, the people affected carry that exposure for life. Spain's fine puts a concrete price on getting this wrong. What matters now is whether 23andMe — a company already in serious financial trouble — can actually make anyone whole, or whether the people whose data was taken are simply left with the risk.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
BleepingComputer · · International

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Closing the Identity Gaps in Critical Infrastructure Security

Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Personal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattack

Seo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cyberattack, exposing up to 10,000 administrative and intelligence records. The data system of the Korea National Diplomatic Academy (KNDA) — an institution affiliated with the... Source

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

NYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from Investigators

The New York Department of Financial Services has reached a $50 million settlement with Swedbank over charges that the bank withheld information from regulators during an investigation, reportedly connected to scrutiny stemming from the 2016 Panama Papers leak.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
DataBreaches.net · · International

Suno Data Breach had a breach in 2025. Why is it first being known now?

Millions here, tens of millions there. Are we all getting breach fatigue by now? Over on HaveIBeenPwned, Troy Hunt reports that Suno experienced a data breach in November 2025, which 404 Media first made public this month: In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the... Source

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
DataBreaches.net · · International

Seoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free Passes

Kim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public bike-sharing service, notifying them of the leaked items and offering compensation such as 30-day passes. The Seoul Facilities Corporation said the same day that it... Source

Who should care: Cybersecurity · Privacy officers · Administrators