23andMe to pay $18 million in new genetics data breach settlement

Genetic Testing Giant 23andMe Agrees to $18 Million Settlement Over Massive Data Breach

In a stark reminder of the importance of robust cybersecurity measures, genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers’ sensitive genetic data. The massive data breach, which occurred in October 2023, compromised the information of 6.9 million customers, including their genetic ancestry details.

The incident was the result of credential-stuffing attacks that went unnoticed for five months, from April 2023 to September 2023. During this time, threat actors stole sensitive data, which was later offered for sale on the dark web as proof of its legitimacy. Some of the stolen genetic profiles were even leaked online, exposing customers’ personal and health-related information.

A multistate investigation launched after the incident revealed that 23andMe lacked basic safeguards against credential-based cyberattacks, such as password blocklisting or multifactor authentication. The company also failed to address unusual login activity and fix known vulnerabilities. Initially, 23andMe denied any breach had occurred, before later blaming customers’ account and password practices for the security lapse.

The settlement requires 23andMe to implement new security measures, including the establishment of a data security advisory board, risk analysis protocols, and continued consumer rights to delete their data. This is a welcome development, as it ensures that customers will have greater control over their sensitive information in the future.

The 2023 data breach has already led to multiple class-action lawsuits, fines, and settlements. In September 2024, 23andMe agreed to pay $30 million to settle one proposed class action lawsuit over the incident. The company’s financial struggles also prompted it to file for Chapter 11 bankruptcy in March 2025, leading to related claims from attorneys general.

This case serves as a stark reminder of the importance of robust cybersecurity measures in protecting sensitive customer data. As we increasingly rely on genetic testing and other services that handle our personal health information, it’s essential that companies take adequate steps to safeguard this data against cyber threats.

So what can we learn from 23andMe’s experience? One key takeaway is the need for ongoing security monitoring and threat detection. Companies must stay vigilant in identifying and addressing potential vulnerabilities before attackers can exploit them. By doing so, they can prevent similar breaches from occurring in the future and protect their customers’ sensitive information.


Source: Bleeping Computer — 2026-07-16