23andMe Settles $18 Million Breach Lawsuit, Agrees to Overhaul Security Measures
A major genetics testing company has agreed to pay a hefty price tag for its failure to protect sensitive customer data. 23andMe, which changed its name to Chrome Holding Co., will shell out $18 million to settle claims from a coalition of 43 attorneys general that it neglected basic cybersecurity safeguards.
The issue began in April 2023 when threat actors launched credential-stuffing attacks against the company’s systems. These types of attacks involve using stolen login credentials to gain unauthorized access to accounts. What followed was a five-month-long breach that went unnoticed by the company, allowing hackers to steal data from approximately 6.9 million customers. The sensitive information included genetic ancestry profiles, which were later sold on the dark web as proof of the stolen data’s legitimacy.
A multistate investigation led by New York Attorney General Letitia James revealed that 23andMe lacked crucial security measures to prevent such attacks, including password blocklisting and multifactor authentication. Furthermore, investigators found that the company failed to monitor for unusual login activity and address known vulnerabilities in its systems. Initially, 23andMe denied any breach had occurred, before shifting blame onto customers’ account practices.
The settlement between 23andMe and the coalition of attorneys general marks a significant step towards ensuring the security of sensitive customer data. As part of the agreement, Chrome Holding Co. will establish a data security advisory board, implement risk analysis protocols, and maintain consumer rights to delete their personal data. New York Attorney General Letitia James emphasized that companies have a duty to protect their customers’ information from hackers, stating that 23andMe “put millions of its customers at risk with its flimsy security measures.”
The consequences of the breach have been far-reaching. Multiple class-action lawsuits and fines have been levied against 23andMe, including a $30 million settlement in September 2024 for one proposed lawsuit over the data breach. The company’s financial struggles prompted it to file for Chapter 11 bankruptcy in March 2025, which led to related claims being filed by James and other attorneys general.
The recent acquisition of 23andMe by the 23andMe Research Institute has brought some stability to the company’s future. However, the settlement serves as a stark reminder of the importance of robust cybersecurity measures for companies handling sensitive customer data.
As this story highlights, even large companies with extensive resources can fall victim to inadequate security practices. For businesses and individuals alike, it is essential to prioritize data protection and regularly review security protocols to prevent such breaches from occurring in the first place.
To avoid becoming the next 23andMe, organizations should conduct thorough risk assessments and implement robust security measures to detect and prevent credential-stuffing attacks. This includes investing in multifactor authentication, monitoring for suspicious activity, and keeping software up-to-date with the latest security patches. By taking proactive steps towards data protection, companies can minimize their vulnerability to cyber threats and safeguard sensitive customer information.
Source: Bleeping Computer — 2026-07-16