Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-20 ยท updated: 2026-07-24 ยท tags: [data-breach, settlement, genetic-data, healthcare, consumer-protection] ยท confidence: high ยท affected_sectors: [healthcare, technology] ยท au_impact: true

23andMe $18M Multi-State Breach Settlement

23andMe, the direct-to-consumer genetic testing company, reached settlements following the massive 2023 data breach that exposed genetic and personal data of millions of customers.

Settlement Details

Field Detail
Amount $18 million (initial multi-state)
Parties 42 state attorneys general, led by Connecticut AG William Tong
Trustee Settlement reached with bankruptcy trustee
Reason 2023 data breach exposing genetic and personal data
Date July 16, 2026 (initial); 42-AG settlement July 23, 2026

A coalition of 42 state attorneys general, led by Connecticut Attorney General William Tong, reached a settlement with the bankruptcy trustee for 23andMe, resolving claims from the 2023 data breach.

Subsequent Enforcement

July 2026 โ€” Spain fines 23andMe nearly $3 million for cybersecurity failings that enabled the 2023 breach. Spanish authorities levied the penalty under data protection law, citing inadequate security measures that allowed the credential-stuffing attack to succeed.

Terms

  • Monetary payment to affected states
  • Security improvement requirements โ€” mandated cybersecurity upgrades
  • Consumer restitution โ€” compensation for affected customers
  • Compliance monitoring and reporting obligations

The 2023 Breach

  • Genetic and ancestry data of millions of customers was exposed
  • Attackers used credential stuffing to access accounts
  • The breach had significant privacy implications given the sensitivity of genetic data
  • Unlike credit card numbers, genetic data cannot be changed after exposure

Significance

This settlement represents one of the largest multi-state breach settlements specifically involving genetic data. The unusual sensitivity of genetic information โ€” immutable and revealing of family relationships โ€” makes this a landmark case for data privacy law.

Australian Significance

Australian genetic testing companies and biobanks should review their security practices in light of this settlement. The Australian Privacy Act's Notifiable Data Breaches scheme would require disclosure of similar incidents.

Related Pages