23andMe Agrees to $18M Multi-State Settlement Over Massive Genetic Data Breach
Attorneys general from across the U.S. have finalized a deal with the DNA testing firm following a 2023 security incident that exposed the profiles of millions.
- An $18 million multi-state settlement has been reached with 23andMe over a 2023 data breach.
- The breach affected roughly 6.9 million users via a credential stuffing attack.
- 23andMe is now required to implement mandatory multi-factor authentication and undergo independent security audits.
- The settlement highlights the unique, permanent risks associated with the theft of genetic and biometric data.
A Coordinated Legal Response
Attorneys general from a broad coalition of states have secured an $18 million settlement with 23andMe, the genetic testing and ancestry company, following a significant data breach that compromised the personal information of millions of users. The agreement concludes a multi-state investigation into the company’s security practices and its failure to adequately protect sensitive consumer information.
The breach, which came to light in late 2023, allowed unauthorized actors to access the data of approximately 6.9 million individuals. According to the office of South Carolina Attorney General Alan Wilson, the settlement addresses allegations that the company failed to safeguard user data, which included ancestry information and health-related predispositions. Similar announcements were echoed by officials across the country, including in New York, Connecticut, Arizona, Texas, and Washington, as state leaders sought to hold the company accountable for its handling of highly sensitive biometric data.
The Scope of the Compromise
The unauthorized access was not a traditional hack of 23andMe’s primary database. Instead, investigators determined that bad actors utilized a technique known as credential stuffing—using passwords stolen from other platforms to access accounts where users had reused their login credentials. Because of the company’s DNA Relatives
feature, which allows users to share data with other relatives, the breach had a cascading effect, exposing information not just of the account holders but also of their extended family members.
The settlement mandates that 23andMe pay $18 million to the participating states. The distribution of these funds varies by jurisdiction; for instance, Washington state is slated to receive over half a million dollars, while other states will receive portions based on their specific consumer protection laws and the number of affected residents. Beyond the monetary penalty, the agreement requires 23andMe to implement more rigorous security protocols, including mandatory multi-factor authentication for all users and improved oversight of third-party data sharing.
Why It Matters: The Vulnerability of Genetic Data
This settlement represents a landmark moment in the regulation of direct-to-consumer genetic testing. Unlike a stolen credit card number, which can be canceled and replaced, genetic data is permanent and unique to the individual. Once this information is exposed, it cannot be reset
or hidden, creating lifelong privacy risks for those whose DNA profiles are now potentially circulating on the dark web.
Legal experts and privacy advocates have long warned that the business model of genetic testing companies relies on the massive aggregation of biological data, which creates a high-value target for cybercriminals. The 23andMe breach serves as a cautionary tale for the industry regarding the responsibility of storing such immutable information. By forcing 23andMe to adopt stricter security measures, the multi-state coalition is attempting to set a new standard for how companies must treat sensitive biometric assets compared to standard consumer data.
Differing Perspectives on Accountability
The reaction to the settlement has been a mixture of relief and continued skepticism. State officials have framed the outcome as a significant victory for consumer rights. Texas Attorney General Ken Paxton noted that the settlement underscores the necessity for companies to prioritize user privacy, particularly when dealing with health-related information.
However, consumer privacy advocates remain critical of the industry’s overall trajectory. While the $18 million figure is substantial, some critics argue that the penalty is relatively small compared to the potential long-term damage caused by the exposure of millions of genetic profiles. Furthermore, there is ongoing debate about whether companies should be allowed to store such granular, identifying data in perpetuity, even if they implement robust security measures. For many users, the primary concern remains that no amount of financial compensation can undo the reality that their biological blueprint has been compromised.
What’s Next for 23andMe Users
Following this settlement, 23andMe is under a court-ordered mandate to overhaul its security infrastructure. The company must provide regular, independent security audits to the states to ensure compliance with the new standards. For the millions of users whose data was involved in the breach, the path forward involves vigilance.
The states involved in the settlement are encouraging affected consumers to verify their account security, enable multi-factor authentication, and remain alert for signs of identity theft. While the legal chapter of this specific breach is closing, the broader conversation regarding the protection of genetic privacy is likely to intensify, with legislators in several states already considering stricter regulations on how biotech firms collect, store, and share biological data.