State AGs Reach Novel Multistate Settlement With Genetic Testing Company 23andMe
A coalition of 42 state attorneys general has secured a $150 million settlement with 23andMe following a significant 2023 data breach. The incident compromised the personal and genetic information of approximately 6.9 million customers. While the headline figure is $150 million, the actual cash payout is limited to $18 million due to the company's ongoing Chapter 11 bankruptcy proceedings. Affected users may still file claims for restitution as part of the legal resolution.
The breach occurred via credential stuffing, a method where attackers use stolen usernames and passwords to gain unauthorized account access. Investigative findings show that 23andMe failed to implement standard security measures such as multifactor authentication or effective rate limiting. These gaps allowed hackers to scrape sensitive details including ancestry reports, family tree data, and genetic profiles.
This case sets a new standard for how regulators treat data privacy during corporate bankruptcy. The attorneys general intervened directly in the bankruptcy court to mandate strict security protocols for the company’s new owners, the TTAM Research Institute. These conditions include ongoing independent oversight and the preservation of consumer data deletion rights. This action demonstrates that bankruptcy filings do not shield companies or their successors from state enforcement authority regarding consumer privacy.
The settlement signals an era of increased scrutiny for any business handling genomic or biometric data. With multiple states enacting specific genetic privacy laws, attorneys general are signaling that they will aggressively pursue firms that do not maintain rigid security standards. Companies should view this outcome as a clear indicator that data management practices are subject to high-level regulatory monitoring regardless of their financial status.

