23andMe Reaches $18 Million Settlement Over Data Breach Affecting 6.9 Million Customers

23andMe has reached an $18 million settlement with 41 states and the District of Columbia over claims that cybersecurity failures allowed hackers to access information tied to 6.9 million customers in a 2023 data breach.

The agreement resolves government claims against the former parent company of 23andMe, now known as Chrome Holding Co., as part of its bankruptcy. State investigators accused 23andMe of failing to use basic safeguards against credential stuffing and allowing suspicious account activity to continue for months without an effective response.

Credential stuffing occurs when hackers take usernames and passwords stolen from one company and test them on accounts belonging to another service. The method often succeeds when people reuse the same login information across several websites.

State officials claim 23andMe did not require multifactor authentication or compare customer passwords with lists of credentials exposed in earlier breaches. The company also allegedly lacked adequate limits on repeated login attempts and systems that could block or quickly identify suspicious activity.

Unauthorized access began in April 2023 and continued through September, according to the multistate investigation. 23andMe disclosed the breach in October 2023.

Hackers initially gained entry to individual accounts and then used a feature that allowed customers to connect with genetic relatives. That access expanded the amount of information available and ultimately exposed data linked to millions of users, including genetic ancestry information and other personal details. Information tied to one customer could also reveal details about biological relatives who never submitted their own DNA.

23andMe maintained that attackers used passwords obtained from other breaches and pointed to customers who reused their login credentials. State investigators argued that password reuse did not excuse the company’s alleged failure to protect against a common form of cyberattack.

Many state privacy, data security and consumer protection laws require companies that collect personal information to use reasonable safeguards. Whether a company’s security was reasonable may depend on the type of information it held, the risks it knew about, the protections available and how it responded to warning signs.

Investigators claim 23andMe failed to address known weaknesses and properly test parts of its platform. They also allege that poor logging and monitoring allowed the attack to continue for about five months despite a sharp rise in login attempts that should have signaled automated activity.

Under the terms of the settlement, the participating government authorities will divide $18 million. Each office may use its share for purposes allowed under state law, including civil penalties, investigation costs, privacy enforcement, consumer education and, in some states, consumer relief.

The agreement also places five-year restrictions on Chrome Holding Co. and related entities winding down the bankruptcy. They will be barred from selling goods or services directly to consumers and from collecting or keeping personally identifiable information, apart from records the bankruptcy trust must retain to finish its work.

23andMe filed for Chapter 11 bankruptcy protection in March 2025. Government entities later submitted claims tied to the breach totaling about $100 billion, including amounts that had not been finally calculated or proven.

For bankruptcy purposes, the covered claims will be recorded at $150 million, but the governments’ total cash recovery is capped at $18 million. The $150 million figure is part of how the claims will be treated in the bankruptcy. It is not an additional payment or a court award.

California did not join the settlement because it filed a separate lawsuit against 23andMe. On July 10, a bankruptcy judge ruled that the state cannot seek monetary relief under the company’s Chapter 11 reorganization plan, leaving California’s claims outside the multistate agreement. California may continue to pursue nonmonetary remedies.

Once the payment is made, the participating states will release their covered breach claims against the debtor entities, the wind-down trust and other named parties. The agreement does not include an admission of liability. Its releases do not apply to 23andMe Research Institute, formerly known as TTAM Research Institute, which acquired the company’s customer data and other assets during the bankruptcy.

The agreement remains subject to approval by the U.S. Bankruptcy Court for the Eastern District of Missouri. Responses are due August 3, and a hearing is scheduled for August 10. If approved, the Plan Administration Trust must distribute the $18 million within 10 business days.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *