23andMe, now operating as Chrome Holding, has secured a $16.5 million settlement from its cyber insurers as part of its Chapter 11 bankruptcy proceedings. The agreement involves the insurers buying back unused cyber insurance coverage, with the funds earmarked to pay creditors whose claims are covered by the company's cyber policies, including those related to ongoing cyberattack litigation. The settlement also stipulates that Chrome will indemnify the insurers for claims up to the settlement amount and release them from further obligations related to the policies.
The bankruptcy court approved the settlement, which is part of a broader restructuring that included the sale of 23andMe's Personal Genome Service and Research Services business lines to TTAM Research Institute for $305 million. Under TTAM's ownership, 23andMe continues to provide DNA health and ancestry testing services. The settlement provides a mechanism for addressing outstanding cyber-related claims as the company navigates its financial and legal challenges.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
During Chapter 11 proceedings, bankrupt 23andMe Holding, renamed Chrome Holding, reached a court-approved settlement with its cyber insurers to buy back $16.5 million in unused cyber insurance coverage. The funds are designated for covered creditor and claimant losses tied to cyber and privacy litigation, including the 2023 breach and Lemonaid Health pixel-tracking claims.
By the time of the bankruptcy settlement, court records showed that nearly $8.5 million of the cyber insurance limits had already been approved for defense costs tied to covered matters. This reduced the unused coverage remaining under the policies.
TTAM Research Institute, founded by 23andMe co-founder Anne Wojcicki, acquired key 23andMe business lines in July 2025. It said it would maintain privacy commitments and applicable legal protections for customer data.
In October 2023, 23andMe suffered a credential stuffing incident that later became the basis for cyberattack litigation. Reporting says the attack affected about 7 million customers worldwide.
23andMe's cyber insurance program for the relevant claims period began with $25 million in aggregate coverage under policies running from May 1, 2023, to May 1, 2024. The policies were eroding, meaning defense costs reduced the remaining limits available for claims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.