New York, Connecticut and other states settle with 23andMe in $18 M breach deal
State attorneys general secured a multistate settlement that allocates $18 million to victims of 23andMe’s 2023 genetic‑data breach, with specific payouts to Illinois, North Carolina and others.
- 23andMe agreed to an $18 million multistate settlement after a 2023 breach exposed customers' DNA data.
- Illinois receives $500,000; North Carolina gets $666,000; New York and Connecticut settled without disclosed amounts.
- Arizona, Wisconsin, the Red Lake Nation and 18 other jurisdictions joined the nationwide deal.
- The settlement includes a court‑appointed monitor to enforce new security measures and may spur further privacy legislation.
State attorneys general across the United States have reached a coordinated settlement with direct‑to‑consumer genetics company 23andMe, resolving claims tied to a 2023 data breach that exposed customers’ genetic information. The agreement caps total compensation at $18 million, with individual states such as Illinois and North Carolina receiving earmarked payments, while New York and Connecticut have also secured settlements whose exact figures were not disclosed.
Core developments
Twenty‑one states, the District of Columbia and the Red Lake Nation have joined a multistate settlement that stems from 23andMe’s Chapter 11 bankruptcy filing after the breach. The collective settlement amount is $18 million, according to the filing documents referenced by multiple outlets.AZ Family Urban Milwaukee The settlement framework distributes funds to state‑level claimants, with several states reporting the precise amounts they will receive.
Illinois will be allocated $500,000, a figure disclosed by the state’s legal team in a filing that highlighted the company’s liability for the unauthorized access to genetic data.RiverBender.com North Carolina secured a $666,000 award, representing the state’s share of the broader $18 million pool.WECT New York and Connecticut announced that they have reached settlement agreements with 23andMe, but the public statements did not disclose the monetary terms.WSHU
Arizona formally joined the nationwide settlement, aligning its claim with the $18 million fund, though a specific allocation for the state was not detailed in the report.AZ Family Wisconsin’s Department of Justice, together with a coalition of consumer‑advocacy groups, also affirmed participation in the settlement, emphasizing a collaborative approach to securing restitution for residents.Urban Milwaukee The Red Lake Nation, represented by Attorney General Jason Ellison, likewise entered the multistate agreement, signaling that tribal entities are included in the remediation effort.Red Lake Nation News
Why it matters
The 23andMe breach is one of the most consequential exposures of genetic data in recent memory, affecting millions of consumers who submitted DNA samples for ancestry and health insights. Unlike typical data breaches that involve passwords or credit‑card numbers, the compromised information includes immutable biological markers that can reveal health predispositions, familial relationships and, potentially, ethnic origins. The settlement therefore touches on a broader debate about how genetic information should be guarded, who bears responsibility when it is mishandled, and what remedies are appropriate for victims.
Legal scholars note that the settlement’s reliance on Chapter 11 bankruptcy proceedings is a strategic choice by 23andMe to limit its exposure while still providing a pathway for compensation. By pooling claims into a single fund, the company avoids a cascade of individual lawsuits that could have driven the liability into the billions. However, consumer‑rights advocates warn that the $18 million total may fall short of addressing the full scope of harm, especially given the long‑term nature of genetic privacy risks.
From a regulatory perspective, the coordinated action of state attorneys general underscores a growing willingness to treat genetic data with the same seriousness afforded to financial or health‑care records. Several states have already passed or are considering legislation that expands consumer protections for biometric and genetic information, reflecting a policy shift toward pre‑emptive safeguards rather than reactive litigation.
Differing viewpoints and reactions
State officials have generally framed the settlement as a victory for consumers. The New York Attorney General’s office described the agreement as “a step toward accountability for a company that failed to protect some of the most sensitive personal data in the world,” while Connecticut’s attorney general echoed that sentiment, emphasizing the importance of securing “fair compensation for affected residents.”WSHU
Consumer‑advocacy groups, however, expressed mixed feelings. A coalition led by the Wisconsin Department of Justice praised the multistate coordination but cautioned that the settlement’s size may not fully reflect the potential for future misuse of genetic data. “While any restitution is better than none, the value of a person’s DNA cannot be measured in dollars,” a spokesperson said, referencing the ongoing risk of re‑identification and discrimination.Urban Milwaukee
Industry observers noted that 23andMe’s decision to settle rather than contest the claims could signal a broader industry trend. “Companies that handle genetic data are now seeing that the legal and reputational stakes are too high to gamble on continued litigation,” said a technology‑law analyst, citing the settlement as evidence that “settlement frameworks may become the default mechanism for resolving such breaches.”
What’s next
The settlement fund will be distributed over the coming months, with each participating state responsible for processing claims from its residents. Illinois, North Carolina, and other states have already begun notifying eligible claimants about the application process, which typically requires proof of 23andMe account ownership during the breach window.
Beyond the immediate payouts, the agreement includes provisions for ongoing oversight. A court‑appointed monitor will supervise 23andMe’s compliance with data‑security reforms, and the company has pledged to implement enhanced encryption, stricter access controls and regular third‑party audits. The monitor’s reports will be filed publicly, offering transparency into how the firm addresses the vulnerabilities that led to the breach.
Legislatively, the settlement is expected to accelerate discussions in several state capitals about expanding biometric‑data statutes. Lawmakers in New York and Connecticut have already introduced bills that would require explicit consent for any secondary use of genetic information, and similar proposals are emerging in Wisconsin and Arizona.
Finally, the settlement does not preclude additional legal action. Victims whose claims were not covered by the $18 million pool, or who seek punitive damages, may still pursue separate lawsuits, especially if future data exposures are linked to the same breach. As the genetics industry continues to grow, the 23andMe case serves as a cautionary tale for both consumers and companies navigating the delicate balance between scientific innovation and privacy protection.