Spanish regulator fined 23andMe over safeguards for genetic data
THE BRIEF
According to the enforcement decision, 23andMe learned about the breach after a sample of stolen information was offered on Reddit. The company waited 12 days before notifying Spanish authorities. The regulator criticized safeguards around highly sensitive genetic information, including the absence of mandatory multifactor authentication and insufficient controls on repeated data access and downloading. The original attack used credential stuffing, where passwords stolen elsewhere are tried against another service. The decision concerns historical conduct, but the practical lesson remains current: reused passwords can expose information that cannot be replaced like a payment card. 23andMe later reached a separate settlement with US state attorneys general. The fine, affected figures and cited control failures are documented by the regulator. For affected people, the practical response should follow confirmed notices rather than speculation. Organizations should preserve records, identify responsible owners and communicate clearly about the known scope. Individuals should use official contact channels, review relevant accounts or devices and be cautious of follow-up messages that exploit publicity around the incident.
WHY IT MATTERS
Genetic data can reveal family relationships, ancestry and health-related characteristics, so exposure may affect relatives as well as the account holder. Unlike a password, DNA information cannot be reset after a breach. Delayed notification also reduces the time people have to secure linked accounts and prepare for targeted scams. Companies handling durable sensitive information need stronger default authentication, limits on bulk access and rapid incident reporting. Customers should treat these services differently from ordinary entertainment accounts because the long-term privacy consequences are fundamentally different.
WHO SHOULD CARE
Current and former genetic-testing customers, their relatives, privacy officers and organizations handling biometric or health-related information should care. The decision shows that optional security and weak download controls may be inadequate when a service stores information that remains sensitive throughout a person’s lifetime.
WHAT TO DO NOW
- Use a unique password and enable multifactor authentication on genetic-testing accounts.
- Review connected applications, shared family profiles and downloadable-data permissions.
- Remove stored samples or close accounts if the continuing benefit no longer justifies the privacy risk.
- Be cautious of messages referencing ancestry, relatives or breach compensation.
- Organizations should rate-limit bulk access and make strong authentication the default for sensitive data.
VERIFICATION NOTE
Verified through the Spanish AEPD enforcement decision reported by The Record. The fine, notification delay, Spanish and global impact figures, and cited authentication weaknesses come from the regulator. The brief distinguishes that enforcement finding from later US settlement activity and does not imply that every exposed person suffered fraud or medical harm.