Genetic testing giant 23andMe has agreed to an $18 million settlement with 43 attorneys general following a catastrophic failure to protect customer DNA profiles.

Key Takeaways

  • 23andMe will pay $18 million to settle claims regarding inadequate genetic data protection.
  • The breach, occurring between April and September 2023, compromised 6.9 million users.
  • Investigations revealed a lack of basic safeguards like multi-factor authentication (MFA).
  • The settlement mandates new security protocols and a data security advisory board.

In a landmark settlement, genetic testing firm 23andMe (now Chrome Holding Co.) has agreed to pay $18 million to resolve claims brought by a coalition of 43 attorneys general. The legal action stems from the company's failure to safeguard the highly sensitive genetic information of millions of its users.

The Anatomy of a Massive Breach

The crisis traces back to a massive breach disclosed in October 2023, which was the result of undetected credential-stuffing attacks that persisted for five months—from April to September 2023. During this period, threat actors successfully accessed the records of approximately 6.9 million customers. The stolen data included intimate genetic ancestry information, much of which was subsequently leaked on the dark web as proof of its legitimacy, posing an unprecedented risk to individual privacy.

Systemic Security Failures Revealed

A multi-state investigation, spearheaded by New York Attorney General Letitia James, uncovered systemic negligence within 23andMe's infrastructure. The investigation found that the company lacked fundamental cyber defenses, such as multi-factor authentication (MFA), password blocklisting, and effective intrusion prevention systems. Rather than proactively addressing unusual login patterns, the company initially denied the breach and attempted to shift the blame onto the security practices of its customers.

A Pattern of Legal and Financial Turmoil

This settlement is just one of many legal hurdles for the company. 23andMe has faced a cascade of challenges, including a $30 million class-action settlement in California and a £2.31 million fine from the UK's Information Commissioner's Office. Adding to its woes, the company filed for Chapter 11 bankruptcy in March 2025, navigating a complex restructuring and asset sale process. The new settlement mandates the creation of a data security advisory board and stricter risk analysis protocols to prevent future catastrophes.