Wire · founder news, decoded · opportunities
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
◆ Published
21 July 2026
◆ Topic
opportunities
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
Spain's data regulator fined 23andMe €2.4 million for cybersecurity failings that enabled a 2023 credential stuffing breach affecting 6.9 million users, citing missing multifactor authentication, inadequate IP-based access controls, and delayed breach notification as GDPR violations.
This Wire brief sits within Fusion42's coverage of Digital Health. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you're collecting genetic data in Europe, multifactor authentication and per-IP download limits are now table-stakes - regulators are fining on the gap between what you say you'll do in a risk disclosure and what your actual security looks like. The fine is small; the pattern of enforcement across US states and EU regulators moving in parallel is the real signal.
◆ Related on Wire
- Spain: AEPD fines Vodafone €1,050,000 for unlawful data disclosure and ...18 July 2026
- Italy fines WINDTRE €1.7 million over security flaws behind two data breaches20 July 2026
- Spain: AEPD fines El Español €20,000 for publishing identifiable video involving minor18 July 2026
- European Commission fines AliExpress €550 million for DSA breaches21 July 2026
- EU Fines AliExpress €550 Million Over Illegal Products in Landmark Digital Services Crackdown21 July 2026
- ETid-3173: GDPR fine against Société Wallonne des Eaux (Belgium, 2026)19 July 2026
◆ Topics
Digital Health · gdpr-enforcement · genetic-data · breach-notification · mfa-mandate · consumer-privacy