
23andMe to Pay $18M in Genetic Data Breach Settlement
.webp)
23andMe has agreed to pay $18 million to a coalition of 43 state attorneys general. The deal settles claims tied to the company's 2023 data breach. It counts among the largest genetic data breach settlement cases on record in the US. The company now operates as Chrome Holding Co., but the failures behind the case trace back to its earlier security setup.
The breach itself was disclosed in October 2023. Hackers ran credential-stuffing attacks against customer accounts for five months, from April to September that year, and nobody noticed. By the time 23andMe caught on, attackers had already pulled data belonging to 6.9 million customers, including sensitive genetic ancestry records.
What Investigators Found
New York Attorney General Letitia James led the multistate investigation that followed. Her office found that 23andMe had skipped security fundamentals most companies treat as standard. There was no password blocklisting. There was no multifactor authentication, and rate limiting on login attempts was inadequate too.
Intrusion prevention and breach-detection monitoring were also missing, so the five-month attack window went unnoticed. Investigators found that 23andMe ignored unusual login activity and left known vulnerabilities unpatched. Instead of moving quickly, the company reportedly denied a breach had happened at all, then shifted blame onto customers' own password habits.
That response drew sharp criticism from James. She said the company put millions of customers at risk with weak security measures. The coalition's action, she added, forces 23andMe to answer for the failure. It also puts new rules in place to protect the people whose data was exposed.
Part of what makes this settlement over the 23andMe data breach notable is the type of data involved. Attackers did not simply steal emails and passwords. They accessed genetic ancestry information tied to real identities, then sold portions of it on dark web forums. Some stolen profiles were leaked publicly as proof the data was genuine, exposing family and ancestry details that millions of people never expected to see for sale.
New Security Requirements
The settlement does more than close the books financially. It requires new security obligations at TTAM, the nonprofit entity now overseeing the former 23andMe assets. A data security advisory board must be established, and formal risk analysis protocols are now mandatory. Customers also keep their ongoing right to delete their genetic data from the platform.
Those requirements matter because genetic data cannot be reset the way a password can. Once ancestry and health-related genetic information leaks, it stays exposed permanently. That permanence is likely why regulators pushed for structural fixes instead of a fine alone.
A Costly Pattern Since 2023
This $18 million payment is far from the only cost tied to the original breach. The 2023 incident sparked a wave of class-action lawsuits. It also prompted 23andMe to rewrite its Terms of Use that November, making arbitration harder for customers to avoid. In September 2024, the company agreed to pay $30 million to settle one of those proposed class actions.
Financial pressure mounted alongside the legal exposure. 23andMe filed for Chapter 11 bankruptcy in March 2025 and began selling off its assets. That filing pushed James and 27 other attorneys general to sue separately, aiming to protect customers' genetic data throughout the bankruptcy process.
Regulators outside the US weighed in too. In June 2025, the UK's Information Commissioner's Office fined 23andMe £2.31 million, roughly $3.12 million, citing serious security failings behind the breach. The regulator called the incident "profoundly damaging" for those affected. A month later, TTAM Research Institute, a nonprofit now led by23andMe co-founder Anne Wojcicki, completed a $305 million acquisition of the company's assets.
Taken together, the fines and settlements linked to this one breach now total well over $50 million. A single security failure, left unresolved for five months, has generated years of legal and financial fallout. That fallout still has not fully settled.
What This Means Going Forward
For companies handling sensitive personal data, this case sets a clear expectation. Regulators no longer accept a payout on its own. They want binding commitments that fix the practices which allowed a breach to happen, backed by oversight like advisory boards and mandatory risk assessments.
For consumers, the data breach settlement is a reminder that genetic information carries risks that outlast any single company's ownership. Even after bankruptcy and a change of ownership, the obligations tied to protecting that data followed the assets to their new nonprofit steward. Anyone who submitted DNA data to 23andMe over the years still has the right to request deletion. That right holds no matter who controls the platform today.
The case also points to how preventable credential-based attacks tend to be. Basic controls, including multifactor authentication and proper rate limiting, could have stopped the 2023 intrusion before it started. Their absence turned a routine security gap into a costly breach. The fallout has now cost 23andMe tens of millions of dollars, years of litigation, and a change in corporate ownership.
Subscribe to receive the latest blog posts to your inbox every week.