Infosecurity

23andMe Hit With $18m Settlement and Strict New Security Mandates After 2023 Breach

Published

on

A Landmark Settlement for Genetic Privacy

More than two years after cybercriminals stole the genetic profiles of over six million people, 23andMe has agreed to pay $18 million and submit to a sweeping set of new security mandates. A bipartisan coalition of 42 US state attorneys general, led by New York Attorney General Letitia James, finalized the deal in July 2025.

The settlement is not just about the money. It forces the company—and its new owner, TTAM Research—to adopt a far stricter data protection regime. New York alone will receive more than $705,000 from the payout.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” James said in a statement. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet.”

How the 23andMe Data Breach Happened

The October 2023 incident was not a sophisticated hack of 23andMe’s core servers. It was a credential stuffing attack—a brute-force method where attackers use usernames and passwords leaked from other sites to break into accounts.

The company admitted at the time that the breach was enabled by customers’ weak password habits and the widespread absence of multi-factor authentication (MFA). Once inside, the attackers scraped profile information tied to ancestry results, eventually accessing data from 6.9 million users.

The fallout was immediate and lasting. By March 2025, 23andMe filed for Chapter 11 bankruptcy protection. In June, James and 27 other attorneys general sued the company to safeguard Americans’ genetic information during the bankruptcy process.

What the $18m Settlement Requires

The settlement imposes several binding security requirements on 23andMe and TTAM Research, the nonprofit formed by former CEO Anne Wojcicki that purchased the customer data.

  • Mandatory risk analysis: The company must conduct regular, documented assessments of its security posture.
  • An Advisory Board on data security: A new oversight body will monitor compliance and recommend improvements.
  • Consumer right to delete: Customers must retain a clear, easy-to-use option to erase their genetic data from the company’s systems.

These measures are designed to prevent a repeat of the 2023 disaster. The settlement also prohibits misleading statements about data protection practices.

This is not the only financial penalty 23andMe faces. A US bankruptcy judge approved a separate $46.75 million fund on July 7, 2025, to compensate victims directly. However, on July 10, the same judge ruled that California cannot seek additional damages from the company due to the Chapter 11 reorganization plan, though the state has 14 days to amend its lawsuit to remove monetary claims.

Regulatory Fines Pile Up Globally

The US settlement is just one piece of a much larger global enforcement puzzle. In July 2026, the Spanish privacy watchdog fined 23andMe €2.4 million ($2.75 million) after finding that 2,642 customers residing in Spain were affected by the breach.

A year earlier, in June 2025, the UK’s Information Commissioner’s Office levied a £2.3 million ($3.1 million) fine for failing to protect customers’ special category data—a classification that includes genetic information, which is among the most sensitive types of personal data under UK law.

These overlapping penalties signal that regulators on both sides of the Atlantic are taking genetic privacy breaches with extreme seriousness.

What This Means for the Future of Genetic Testing

The 23andMe case is a cautionary tale for the entire direct-to-consumer genetic testing industry. When customers mail in a saliva sample, they are trusting the company with data that cannot be changed—unlike a password or credit card number. A leaked genetic profile is permanent.

The new security mandates at TTAM Research set a precedent. Other firms in the space, including AncestryDNA and MyHeritage, will be watching closely. If state attorneys general are willing to impose structural reforms—not just fines—on a bankrupt company, the bar for data protection across the industry just got higher.

For consumers, the lesson is blunt: enable MFA on every account that holds sensitive data, and think twice before sharing your DNA with any private company. The settlement may close the legal case, but the questions about trust in the genetic testing industry are far from settled.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version