23andMe Settles Data Privacy Claims
A coalition of attorneys general has secured an $18 million settlement from 23andMe regarding a 2023 genetic data breach.
The genetic testing industry faces a significant reckoning as legal actions continue to mount regarding the handling of sensitive consumer information. Following a protracted investigation into a major security incident, the entity formerly known as 23andMe has reached a financial resolution with a multi-state coalition of authorities.
The Scope of the Compromise
The investigation centers on a breach initially disclosed in October 2023. Threat actors utilized credential-stuffing techniques to gain unauthorized access to the company's platform, an intrusion that remained undetected for a span of five months between April 2023 and September 2023. This event resulted in the theft of personal information belonging to 6.9 million customers, including details regarding their genetic ancestry.
Regulatory Findings on Security Lapses
According to findings shared by the New York Attorney General, the firm lacked fundamental security controls necessary to prevent such exploitation. Specifically, the investigation identified an absence of multifactor authentication and password blocklisting, alongside insufficient intrusion prevention and rate-limiting protocols. The company reportedly attempted to shift responsibility toward users' personal password habits while initially denying the occurrence of a breach altogether.
Companies have a duty to protect their customers' personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures.
— Letitia James, New York Attorney General
Financial and Legal Consequences
The incident has triggered a series of legal actions, including class-action litigation and international regulatory intervention. The firm filed for Chapter 11 bankruptcy in March 2025, eventually leading to an acquisition by the TTAM Research Institute. The financial and operational impact is summarized by the following data points:
- $18 million: Settlement amount paid to the coalition of 43 attorneys general.
- $30 million: Settlement amount agreed upon in a September 2024 class-action lawsuit.
- $3.12 million: Equivalent fine in GBP (£2.31 million) issued by the UK Information Commissioner's Office.
- $305 million: Acquisition price paid by the TTAM Research Institute to secure company assets.
Implications for Consumer Privacy
This resolution underscores the significant legal and financial stakes for organizations that aggregate large volumes of sensitive biometric data. The case highlights how failures in basic identity management—such as the lack of breach-detection monitoring—can leave entities vulnerable to long-term litigation and regulatory scrutiny. For businesses, this suggests that technical debt in security architecture, specifically regarding account access controls, creates substantial liability that persists even through organizational restructuring and bankruptcy proceedings.
Sources
- BleepingComputer Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.