ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Data breach costs 23andMe $46.75 million in court-approved settlement

A California bankruptcy court judge has ruled that 23andMe must pay $46.75 million in compensation following an October 2023 data breach that exposed the personal information of 6.4 million users.

Linked InXFacebook
bookmark_borderSave to Library

A California bankruptcy court has ordered 23andMe to pay $46.75 million in compensation over an October 2023 data breach that compromised the personal information of 6.4 million users.

 

In October 2023, 23andMe suffered a significant data breach where a hacker accessed sensitive health data by exploiting stolen usernames and passwords. The attacker used 23andMe’s DNA Relatives and Family Tree features to view additional information about account holders’ relatives. Some of the stolen data, including details on users of Ashkenazi and Chinese heritage, was posted on the dark web, further escalating concerns over the privacy of genetic information.

 

While the breach directly affected only a limited portion of 23andMe’s total accounts, the company confirmed that the personal data of 6.4 million users in the U.S. was compromised.

 

The breach triggered regulatory investigations and penalties, including a £2.31 million fine from the UK’s Information Commissioner’s Office (ICO). The watchdog found that 23andMe had failed to implement adequate safeguards to protect sensitive user data before the incident occurred.

 

Recently, the BBC reported that on July7, a California bankruptcy court judge has asked Chrome Holding, which acquired 23andMe following its bankruptcy last year, must pay $46.75 million (approximately £35 million) in compensation. 

 

According to the ruling, the settlement amount must be transferred to Kroll Restructuring, the firm representing the victims, within five business days of July 7. Kroll will then oversee the distribution of the compensation to eligible claimants.

 

In September 2024, 23andMe agreed to pay $30 million to settle dozens of lawsuits stemming from the data breach. Alongside the financial compensation, 23andMe pledged to implement a range of security enhancements, including better password protections, mandatory multi-factor authentication, and annual cybersecurity audits.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543