Spanish regulators have imposed a nearly $3 million fine on genetic testing company 23andMe for cybersecurity shortcomings that led to a significant data breach in 2023, affecting 6.9 million individuals worldwide, including over 2,600 Spanish citizens1. The Agencia Española de Protección de Datos (AEPD) determined that 23andMe's inadequate security measures enabled the breach, resulting in the exposure of sensitive user data. This decision underscores the importance of robust cybersecurity protocols, particularly for companies handling sensitive personal information. The fine serves as a reminder that regulatory bodies are increasingly holding organizations accountable for failing to protect user data. So what matters to practitioners is that this fine highlights the need for proactive investment in cybersecurity measures to prevent similar breaches and avoid hefty penalties.
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
⚡ High Priority
Why This Matters
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9.
References
- The Record. (2026, July 21). Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack. The Record. https://therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach
Original Source
The Record Cyber
Read original →