Breaking
SecurityDeveloping Story

23andMe Settles Data Privacy Claims

A coalition of attorneys general has secured an $18 million settlement from 23andMe regarding a 2023 genetic data breach.

··1 month ago·2 min read
red and black love lock
Photo by FlyD on Unsplash

The genetic testing industry faces a significant reckoning as legal actions continue to mount regarding the handling of sensitive consumer information. Following a protracted investigation into a major security incident, the entity formerly known as 23andMe has reached a financial resolution with a multi-state coalition of authorities.

The Scope of the Compromise

The investigation centers on a breach initially disclosed in October 2023. Threat actors utilized credential-stuffing techniques to gain unauthorized access to the company's platform, an intrusion that remained undetected for a span of five months between April 2023 and September 2023. This event resulted in the theft of personal information belonging to 6.9 million customers, including details regarding their genetic ancestry.

Regulatory Findings on Security Lapses

According to findings shared by the New York Attorney General, the firm lacked fundamental security controls necessary to prevent such exploitation. Specifically, the investigation identified an absence of multifactor authentication and password blocklisting, alongside insufficient intrusion prevention and rate-limiting protocols. The company reportedly attempted to shift responsibility toward users' personal password habits while initially denying the occurrence of a breach altogether.

Companies have a duty to protect their customers' personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures.

— Letitia James, New York Attorney General

Financial and Legal Consequences

The incident has triggered a series of legal actions, including class-action litigation and international regulatory intervention. The firm filed for Chapter 11 bankruptcy in March 2025, eventually leading to an acquisition by the TTAM Research Institute. The financial and operational impact is summarized by the following data points:

  • $18 million: Settlement amount paid to the coalition of 43 attorneys general.
  • $30 million: Settlement amount agreed upon in a September 2024 class-action lawsuit.
  • $3.12 million: Equivalent fine in GBP (£2.31 million) issued by the UK Information Commissioner's Office.
  • $305 million: Acquisition price paid by the TTAM Research Institute to secure company assets.

Implications for Consumer Privacy

This resolution underscores the significant legal and financial stakes for organizations that aggregate large volumes of sensitive biometric data. The case highlights how failures in basic identity management—such as the lack of breach-detection monitoring—can leave entities vulnerable to long-term litigation and regulatory scrutiny. For businesses, this suggests that technical debt in security architecture, specifically regarding account access controls, creates substantial liability that persists even through organizational restructuring and bankruptcy proceedings.

#data breach#genetics#privacy#cybersecurity#settlement

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories