Spain Fines 23andMe €2.4 M for Credential‑Stuffing Breach Exposing 6.9 M Genetic Profiles
What Happened – In April 2023 a credential‑stuffing attack bypassed weak authentication at 23andMe, allowing attackers to access and download genetic and personal data for roughly 6.9 million users worldwide, including more than 2,600 Spaniards. The company did not notify Spain’s data‑protection authority until 12 days after discovery.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how missing multi‑factor authentication (MFA) and lack of login‑rate limiting directly violate SOC 2 CC6.1 (Logical Access Security) and GDPR‑required safeguards.
- Highlights the need for documented, real‑time access‑control monitoring that can serve as audit evidence of “reasonable security” under SOC 2.
- Shows that delayed breach notification erodes the defensible audit trail required for both GDPR and SOC 2 incident‑response criteria.
Who Is Affected – Direct‑to‑consumer genetics providers, health‑tech SaaS, and any organization handling highly sensitive personal or biometric data.
Recommended Actions –
- Deploy mandatory MFA for all privileged and consumer accounts.
- Implement IP‑based rate‑limiting and anomaly detection on authentication endpoints.
- Update incident‑response playbooks to meet GDPR 72‑hour notification windows and map those steps to SOC 2 CC7.2 (Incident Management).
- Capture MFA enforcement logs and rate‑limit alerts as continuous compliance evidence.
Technical Notes – The attack leveraged credential‑stuffing (reused passwords) against a web portal lacking MFA and per‑IP access throttling. No specific CVE was involved; the flaw was a process/controls gap. Exfiltrated data included DNA profiles, health questionnaires, and personally identifiable information.
Source: The Record