23ANDME

State AGs Reach Novel Multistate Settlement With Genetic Testing Company 23andMe

Dr. Amelia Hart
Dr. Amelia Hart
NewsHue Author
23andMe logo displayed on a digital screen during a public discussion on genetic data security.

A coalition of 42 state attorneys general has secured a $150 million settlement with 23andMe following a significant 2023 data breach. The incident compromised the personal and genetic information of approximately 6.9 million customers. While the headline figure is $150 million, the actual cash payout is limited to $18 million due to the company's ongoing Chapter 11 bankruptcy proceedings. Affected users may still file claims for restitution as part of the legal resolution.

The breach occurred via credential stuffing, a method where attackers use stolen usernames and passwords to gain unauthorized account access. Investigative findings show that 23andMe failed to implement standard security measures such as multifactor authentication or effective rate limiting. These gaps allowed hackers to scrape sensitive details including ancestry reports, family tree data, and genetic profiles.

This case sets a new standard for how regulators treat data privacy during corporate bankruptcy. The attorneys general intervened directly in the bankruptcy court to mandate strict security protocols for the company’s new owners, the TTAM Research Institute. These conditions include ongoing independent oversight and the preservation of consumer data deletion rights. This action demonstrates that bankruptcy filings do not shield companies or their successors from state enforcement authority regarding consumer privacy.

The settlement signals an era of increased scrutiny for any business handling genomic or biometric data. With multiple states enacting specific genetic privacy laws, attorneys general are signaling that they will aggressively pursue firms that do not maintain rigid security standards. Companies should view this outcome as a clear indicator that data management practices are subject to high-level regulatory monitoring regardless of their financial status.

Frequently Asked Questions

How many customers were affected by the 23andMe data breach?+
Approximately 6.9 million customers had their personal and genetic information exposed.
How much of the $150 million settlement will be paid out to states?+
The actual settlement funds are limited to $18 million due to the company's Chapter 11 bankruptcy proceedings.
What specific security failures led to the 23andMe breach?+
The company failed to employ adequate safeguards like multifactor authentication, rate limiting, and password monitoring.
Tags
Dr. Amelia Hart
Dr. Amelia Hart
Dr. Amelia Hart breaks down complex scientific discoveries and space exploration.