ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

23andMe agrees to $18 million settlement following multistate probe into data breach

Genetic testing firm 23andMe has agreed to pay an $18 million settlement to resolve allegations brought by a group of 43 attorneys general that it did not adequately safeguard customers’ genetic information.

Linked InXFacebook
bookmark_borderSave to Library

Genetic testing company 23andMe has agreed to an $18 million settlement to resolve claims from a coalition of 43 state attorneys general claiming that the company failed to properly protect customers’ sensitive genetic data.

 

In October 2023, 23andMe suffered a significant data breach where a hacker accessed sensitive health data by exploiting stolen usernames and passwords. The attacker used 23andMe’s DNA Relatives and Family Tree features to view additional information about account holders’ relatives. Some of the stolen data, including details on users of Ashkenazi and Chinese heritage, was posted on the dark web, further escalating concerns over the privacy of genetic information.

 

While the breach directly affected only a limited portion of 23andMe’s total accounts, the company confirmed that the personal data of 6.4 million users in the U.S. was compromised.

 

The breach triggered regulatory investigations and penalties, including a £2.31 million fine from the UK’s Information Commissioner’s Office (ICO). The watchdog found that 23andMe had failed to implement adequate safeguards to protect sensitive user data before the incident occurred.

 

Following the data breach, New York Attorney General Letitia James and a coalition of state attorneys general conducted a multistate investigation into 23andMe’s data security practices. The investigation found that the genetic testing company failed to adopt critical cybersecurity protections, including safeguards against attacks involving stolen credentials, effective rate limiting and intrusion prevention measures, breach detection and monitoring systems, proper reviews of suspicious login activity, timely fixes for known vulnerabilities, and adequate testing of security features.

 

As a result of the investigation, Attorney General James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement with 23andMe over allegations that the company failed to protect customers’ sensitive genetic information.

 

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe puts millions of its customers at risk with its flimsy security measures.

 

“New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law and strict rules will be put in place to protect their customers,” Attorney General James said.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543