[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fe6h4JCt6fHgl4kLQ6BBJ8mOAQXAXxGJ4LxV6m7bz6Gs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"0ee771ac-48a2-453a-b5eb-5ba238ecb28f","23andme-fined-24m-after-credential-stuffing-breach-exposes-genetic-data-of-spanish-users","f3a5e579-49b5-43dc-b896-f272c5f4b0be","23andMe Fined €2.4M After Credential-Stuffing Breach Exposes Genetic Data of Spanish Users","The 23andMe breach originated from a credential-stuffing attack — a well-understood threat vector that exploits password reuse — indicating insufficient controls such as multi-factor authentication and anomalous login detection were not in place to protect highly sensitive genetic and health data. Compounding the technical failure, the company violated GDPR Article 33 by reporting the breach seven days after detection, well outside the mandatory 72-hour notification window, demonstrating inadequate incident response planning. The sensitivity of the exposed data — including genetic profiles, ethnicity, health information, and biometric details — means the harm to affected individuals is severe and potentially irreversible. This case underscores that organisations handling special-category data under GDPR must apply proportionally stronger technical and procedural safeguards, and must have breach notification workflows tested and ready to execute under regulatory timelines.","**Immediate actions:**\n- Enforce multi-factor authentication (MFA) on all customer-facing accounts, especially those storing special-category data such as genetic or health information.\n- Deploy real-time credential-stuffing detection tools (e.g., rate limiting, device fingerprinting, and compromised-credential checks against known breach databases).\n- Activate and test your GDPR breach notification runbook to ensure the 72-hour regulatory clock is met from the moment of breach detection.\n\n**Long-term improvements:**\n- Conduct a Data Protection Impact Assessment (DPIA) for all processing of special-category data to identify and mitigate risks before incidents occur.\n- Implement a formal Incident Response Plan with clearly assigned roles, escalation paths, and regulatory notification checklists aligned to GDPR Article 33\u002F34 timelines.\n- Apply data minimisation and pseudonymisation techniques to limit the volume and identifiability of sensitive genetic and health data stored in customer-facing systems.\n\n**Detection & monitoring measures:**\n- Deploy continuous monitoring for anomalous authentication patterns, including high-frequency login attempts and logins from unusual geolocations or IP ranges.\n- Integrate threat intelligence feeds to proactively identify if customer credentials or data appear on dark web forums or paste sites.\n- Establish automated alerting thresholds that trigger an incident response workflow within hours of a suspected breach to preserve the 72-hour GDPR notification window.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"GDPR Article 5(1)(f) — Integrity and confidentiality","GDPR Article 25 — Data protection by design and by default","GDPR Article 32 — Security of processing","GDPR Article 33 — Notification of a personal data breach to the supervisory authority","GDPR Article 9 — Processing of special categories of personal data","NIST SP 800-63B — Digital Identity Guidelines (Authentication)","NIST IR-6 — Incident Reporting","NIST PR.AC-7 — Users, devices, and other assets are authenticated","CIS Control 6 — Access Control Management","CIS Control 13 — Network Monitoring and Defense","CIS Control 17 — Incident Response Management","ISO\u002FIEC 27001:2022 — Annex A.5.26 (Response to information security incidents)","ISO\u002FIEC 27001:2022 — Annex A.8.5 (Secure authentication)","published","2026-07-24T16:21:13.758712+00:00","2026-07-24T16:21:13.667+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00140-2025&diff=52491&oldid=0","aepd-spain-ps-00140-2025-8104c5","AEPD (Spain) - PS-00140-2025",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[52,58],{"id":53,"date":54,"edition":55,"title":56,"audio_url":57},"167c93da-62a7-447b-a185-ef897a93e06d","2026-07-26","afternoon","ThreatNoir Weekend Brief — July 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-26\u002Fthreatnoir-afternoon-brief-2026-07-26.mp3",{"id":59,"date":60,"edition":61,"title":62,"audio_url":63},"930bbc16-25e4-42e2-9b08-bcca9eb8f473","2026-07-25","morning","ThreatNoir Weekend Brief — July 25","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-25\u002Fthreatnoir-morning-brief-2026-07-25.mp3"]