23andMe Reaches $18 Million Settlement Over Data Breach Affecting 6.9 Million Customers

by Alexandra Agraz | Jul 22, 2026
Two 23andMe Personal Genome Service boxes on a dark surface with rainbow-colored stripes. Photo Source: Adobe Stock Image

23andMe has reached an $18 million settlement with 41 states and the District of Columbia over claims that cybersecurity failures allowed hackers to access information tied to 6.9 million customers in a 2023 data breach.

The agreement resolves government claims against the former parent company of 23andMe, now known as Chrome Holding Co., as part of its bankruptcy. State investigators accused 23andMe of failing to use basic safeguards against credential stuffing and allowing suspicious account activity to continue for months without an effective response.

Credential stuffing occurs when hackers take usernames and passwords stolen from one company and test them on accounts belonging to another service. The method often succeeds when people reuse the same login information across several websites.

State officials claim 23andMe did not require multifactor authentication or compare customer passwords with lists of credentials exposed in earlier breaches. The company also allegedly lacked adequate limits on repeated login attempts and systems that could block or quickly identify suspicious activity.

Unauthorized access began in April 2023 and continued through September, according to the multistate investigation. 23andMe disclosed the breach in October 2023.

Hackers initially gained entry to individual accounts and then used a feature that allowed customers to connect with genetic relatives. That access expanded the amount of information available and ultimately exposed data linked to millions of users, including genetic ancestry information and other personal details. Information tied to one customer could also reveal details about biological relatives who never submitted their own DNA.

23andMe maintained that attackers used passwords obtained from other breaches and pointed to customers who reused their login credentials. State investigators argued that password reuse did not excuse the company’s alleged failure to protect against a common form of cyberattack.

Many state privacy, data security and consumer protection laws require companies that collect personal information to use reasonable safeguards. Whether a company’s security was reasonable may depend on the type of information it held, the risks it knew about, the protections available and how it responded to warning signs.

Investigators claim 23andMe failed to address known weaknesses and properly test parts of its platform. They also allege that poor logging and monitoring allowed the attack to continue for about five months despite a sharp rise in login attempts that should have signaled automated activity.

Under the terms of the settlement, the participating government authorities will divide $18 million. Each office may use its share for purposes allowed under state law, including civil penalties, investigation costs, privacy enforcement, consumer education and, in some states, consumer relief.

The agreement also places five-year restrictions on Chrome Holding Co. and related entities winding down the bankruptcy. They will be barred from selling goods or services directly to consumers and from collecting or keeping personally identifiable information, apart from records the bankruptcy trust must retain to finish its work.

23andMe filed for Chapter 11 bankruptcy protection in March 2025. Government entities later submitted claims tied to the breach totaling about $100 billion, including amounts that had not been finally calculated or proven.

For bankruptcy purposes, the covered claims will be recorded at $150 million, but the governments’ total cash recovery is capped at $18 million. The $150 million figure is part of how the claims will be treated in the bankruptcy. It is not an additional payment or a court award.

California did not join the settlement because it filed a separate lawsuit against 23andMe. On July 10, a bankruptcy judge ruled that the state cannot seek monetary relief under the company’s Chapter 11 reorganization plan, leaving California’s claims outside the multistate agreement. California may continue to pursue nonmonetary remedies.

Once the payment is made, the participating states will release their covered breach claims against the debtor entities, the wind-down trust and other named parties. The agreement does not include an admission of liability. Its releases do not apply to 23andMe Research Institute, formerly known as TTAM Research Institute, which acquired the company’s customer data and other assets during the bankruptcy.

The agreement remains subject to approval by the U.S. Bankruptcy Court for the Eastern District of Missouri. Responses are due August 3, and a hearing is scheduled for August 10. If approved, the Plan Administration Trust must distribute the $18 million within 10 business days.

Share This Article

If you found this article insightful, consider sharing it with your network.

Alexandra Agraz
Alexandra Agraz is a former Diplomatic Aide with firsthand experience in facilitating high-level international events, including the signing of critical economic and political agreements between the United States and Mexico. She holds dual associate degrees in Humanities, Social and Political Sciences, and Film, blending a diverse academic background in diplomacy, culture, and storytelling. This unique combination enables her to provide nuanced perspectives on global relations and cultural narratives.

Related Articles

Amazon logo on a glass-front office building under a clear blue sky.
Amazon to Pay $2.25 Million to Settle FTC Identity Theft Records Claims

Amazon has agreed to pay $2.25 million to settle federal allegations that it denied identity theft victims access to business records they needed to investigate fraudulent transactions made with their personal information.The Justice Department filed the case June 29 in the U.S. District Court for the District of Columbia after... Read More »

Interior of a GM vehicle featuring a steering wheel and a large touchscreen navigation display on the dashboard.
GM Agrees to $12.75 Million California Settlement Over Driver Data Collection

General Motors has agreed to pay $12.75 million to settle a California lawsuit accusing the automaker of improperly collecting and selling sensitive driver data gathered through its OnStar connected-vehicle system. California Attorney General Rob Bonta announced the settlement on Friday, alleging GM and OnStar disclosed drivers’ names, contact information, geolocation... Read More »

T-Mobile store sign displaying the company logo and branding.
T-Mobile Says Data on 37 Million Customers Stolen

T-Mobile has been hit with a data breach that has impacted about 37 million of its customers. The data breach resulted in the personal identification information of millions of customers across the nation being shared with unauthorized individuals. In a form filed with the U.S. Securities and Exchange Commission on... Read More »