AUSTIN — A coalition of 42 states and the District of Columbia secured an $18 million settlement with genetic testing company 23andMe on July 15, 2026, resolving claims stemming from a 2023 data breach that exposed the personal and genetic ancestry information of 6.9 million consumers worldwide. The settlement addresses failures in cybersecurity practices that allowed hackers to access sensitive customer data, some of which was later posted for sale on the dark web.
The breach, which 23andMe disclosed in October 2023, involved the theft of data from 6.9 million customers globally, including 305,245 in New York. A multistate investigation concluded that 23andMe used unreasonable security practices and failed to implement basic cybersecurity protections such as multifactor authentication, screening for compromised passwords, monitoring unusual login activity, and properly reviewing and testing design features. The company learned of the breach months after the stolen data had already become publicly available and initially denied the incident before blaming consumers’ account settings and password practices.
Texas Attorney General Ken Paxton, who led the coalition, emphasized the legal obligations of companies handling sensitive personal data. “Companies that collect and profit from Texans’ most personal information have a legal duty to protect it,” Paxton said. Texas will receive $1,266,860 from the settlement. New York will receive more than $705,000, and Iowa will receive $429,767.
Although the total amount allocated for the multistate coalition in bankruptcy proceedings was $150 million, recoveries were capped at $18 million due to limited funds in 23andMe’s bankruptcy estate and competing claims. The company filed for bankruptcy protection in March 2025. During those proceedings, 23andMe’s customer data was sold to TTAM Research, a nonprofit formed by the company’s founder and former CEO, which has since been renamed the 23andMe Research Institute. Delaware had initially objected to the sale but withdrew its opposition after the institute agreed to additional privacy protections and consumer rights to control genetic data.
The settlement also imposes new privacy and cybersecurity requirements on 23andMe, including enhanced security standards, comprehensive risk assessments, creation of an independent advisory board, enforcement of state privacy laws, and continued consumer rights to request data deletion. New York Attorney General Letitia James, who in June 2025 had sued 23andMe alongside 27 other attorneys general during the bankruptcy proceedings, said, “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet.” She added, “As a result of our coalition’s action, 23andMe will pay for violating the law and strict rules will be put in place to protect their customers.”
Genetic data is among the most sensitive personal information, and its exposure can have long-term privacy and discrimination implications. The 2023 breach and subsequent bankruptcy of 23andMe underscore the vulnerabilities in the direct-to-consumer genetic testing industry and the critical need for robust cybersecurity safeguards. This settlement establishes enforceable standards intended to prevent future incidents and reinforces state authority to protect residents’ data even when companies restructure or dissolve.
forum Comments (0)
No comments yet. Be the first to comment.