news.mlab.sh
Back to the feed
data-breach

23andMe reaches $18 million settlement with states for massive breach

High
Summary

23andMe has reached a $18 million settlement with 42 state attorneys general due to a significant data breach in 2023 that exposed the genetic and personal information of 6.9 million customers. The company initially denied the breach and blamed users, but now faces stricter data protection requirements and a new research institute operating under increased oversight.

23andMe has reached a $18 million settlement with 42 state attorneys general following a substantial data breach that occurred in October 2023. The breach exposed the genetic and personal data of approximately 6.9 million customers, including ancestry information and other sensitive details. The settlement comes after a multistate investigation identified numerous cybersecurity failings within 23andMe, including a lack of protections against credential-based hacks, insufficient intrusion prevention measures, and failure to address known vulnerabilities. The company initially disputed the existence of a breach and attempted to shift responsibility to its users’ account configurations and password security.

Following the breach, 23andMe filed for bankruptcy protection in March 2025. In June, a Missouri bankruptcy court approved a settlement awarding millions of the breach’s victims a share of a $47 million fund. The settlement mandates new data protection measures for the 23andMe Research Institute, a nonprofit established by 23andMe CEO Anne Wojcicki, which absorbed 23andMe’s assets, including the compromised genetic data.

The institute is required to conduct risk assessments and establish a special board to oversee data security. Furthermore, 23andMe customers retain the right to request the destruction of their genetic samples and deletion of their personal data at any time. The institute will continue 23andMe’s existing practice of sharing and selling de-identified customer data for biomedical research, subject to the same restrictions regarding sharing with employers, insurers, and law enforcement without proper legal authorization. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record.

Read the full article at The Record