← Back

Wire · opportunities

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Published

21 July 2026

Topic

opportunities

Sectors

Digital Health

Geography

Spain

Source

Read at therecord.media

Verified

Fusion42 · 21 July 2026 · Fusion42 review

Spain's data regulator fined 23andMe €2.4 million for cybersecurity failings that enabled a 2023 credential stuffing breach affecting 6.9 million users, citing missing multifactor authentication, inadequate IP-based access controls, and delayed breach notification as GDPR violations.

This Wire brief sits within Fusion42's coverage of Digital Health.

◆ The Wire takeaway

If you're collecting genetic data in Europe, multifactor authentication and per-IP download limits are now table-stakes - regulators are fining on the gap between what you say you'll do in a risk disclosure and what your actual security looks like. The fine is small; the pattern of enforcement across US states and EU regulators moving in parallel is the real signal.

Coverage

1 source · 21 Jul 2026

Related on Wire

Topics

Digital Healthgdpr-enforcementgenetic-databreach-notificationmfa-mandateconsumer-privacy