23ANDME, INC – Violation Found (Spain, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
23ANDME, INC. faced a data breach that exposed sensitive information of over 2,600 customers in Spain. Hackers accessed accounts using stolen credentials, revealing personal and health data. This incident shows the importance of strong security measures for online services.
What happened
A credential-stuffing attack allowed hackers to access customer accounts at 23ANDME, exposing sensitive personal data.
Who was affected
2,642 customers in Spain whose accounts were compromised and personal data was exposed.
What the authority found
The Spanish data protection authority found that 23ANDME did not implement adequate security measures to protect customer data during the breach.
Why this matters
This case highlights the critical need for companies to adopt robust security practices, such as mandatory multi-factor authentication and strong password policies, to protect customer data from breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for 23ANDME, INC in ES
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. 23ANDME, INC - Spain (2025). Retrieved from cookiefines.eu
Last updated: