Industry - Lawsuit
Executive Summary
23andMe will pay $18 million to settle claims from 43 state attorneys general after a 2023 data breach exposed the personal genetic information of 6.4 million U.S. users. Hackers used stolen credentials to access accounts and exploited the company's DNA Relatives feature to view additional data about users' family members, with some information later posted on the dark web. The investigation found 23andMe failed to implement basic security protections including safeguards against credential-s...
What Happened
In October 2023, hackers gained access to 23andMe user accounts using stolen credentials obtained elsewhere. The attackers then exploited the company's DNA Relatives and Family Tree features to view data about account holders' family members, ultimately compromising the personal genetic information of 6.4 million U.S. users. Some of this stolen data, including information about users of Ashkenazi and Chinese heritage, was subsequently posted on the dark web.
Who Is Affected
The breach directly impacted 6.4 million users in the United States whose genetic and personal information was exposed. Family members of direct account holders were also affected even if they did not have their own accounts, because the DNA Relatives feature allowed hackers to access their data through connected accounts. Users of Ashkenazi and Chinese heritage were specifically targeted, with their information shared on dark web forums.
Why It Matters
This breach demonstrates that genetic data, unlike passwords or credit card numbers, cannot be changed once compromised and represents a permanent privacy loss. The investigation by 43 state attorneys general found that 23andMe failed to implement basic security measures including credential stuffing protections, rate limiting, intrusion prevention, breach monitoring, and timely vulnerability fixes. The $18 million settlement and UK fine of £2.31 million establish accountability for companies handling irreversible biometric data and set a precedent for minimum security standards in the genetic testing industry.
What You Should Do
If you are a 23andMe user, enable multi-factor authentication on your account immediately to prevent credential-based attacks. Review your privacy settings, particularly for features like DNA Relatives that share your information with connections, and consider disabling these features if you do not actively use them. Monitor for identity theft or targeted scams, as genetic heritage information could be used for discriminatory purposes or social engineering attacks. Consider whether the benefits of maintaining your account outweigh the risks, given that genetic data cannot be changed if compromised again in the future.
Summary generated from verified sources and reviewed before publication. How we summarize.
Related Events
- Industry - Data BreachJul 20, 2026
A 2023 data breach at genetic testing company 23andMe compromised the genetic da...
- Industry - Data BreachJul 15, 2026
Forty-three states reached an $18 million settlement with 23andMe's bankruptcy t...
- Industry - LawsuitJul 15, 2026
Attorney General Ellison reaches multistate settlement of bankruptcy claims agai...
- Industry - EnforcementJul 14, 2026
Consumer alert: 23andMe hit with $18 million penalty after massive DNA data brea...
- Industry - Data BreachJun 15, 2026
The bankruptcy plan administrator for 23andMe agreed to pay $46.75 million to se...