A coalition of 42 U.S. state attorneys general reached an $18 million settlement with 23andMe over cybersecurity failures tied to the company’s 2023 breach, which exposed genetic and other personal information belonging to 6.9 million people. Authorities said the company failed to defend against credential-based attacks, lacked adequate intrusion prevention, did not properly log and monitor for intrusions, failed to remediate known vulnerabilities, and did not investigate unusual login activity. The settlement also imposes new security and governance requirements on the 23andMe Research Institute, which acquired the company’s assets, including genetic data, after its 2025 bankruptcy, while preserving customers’ rights to delete personal data and destroy genetic samples.
In a related bankruptcy ruling, a U.S. judge held that California cannot seek monetary damages from the company formerly known as 23andMe because its Chapter 11 reorganization plan bars those claims, though the state may still pursue non-monetary remedies. The court said California had participated in the bankruptcy case and had an earlier opportunity to challenge jurisdiction, requiring the state to amend or dismiss its lawsuit to remove claims for civil fines. The bankruptcy process also created a customer claims fund, and the court has authorized $46.75 million in total payouts connected to the breach.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Spain's data protection authority AEPD fined 23andMe €2.4 million for cybersecurity and privacy failings tied to the April 2023 breach, which affected more than 2,600 people in Spain. The regulator said the company lacked adequate safeguards for sensitive genetic data and delayed notifying Spanish authorities by 12 days after learning of the incident.
A coalition of 42 U.S. state attorneys general reached an $18 million settlement with 23andMe over cybersecurity failures tied to the 2023 breach. The agreement imposes new security and governance requirements on the 23andMe Research Institute and preserves customers' rights to destroy genetic samples and delete personal data.
After 23andMe's 2025 bankruptcy, the 23andMe Research Institute acquired the company's assets, including genetic data. This acquisition later became relevant to enforcement and settlement terms tied to the breach.
A U.S. bankruptcy judge ruled that California cannot pursue monetary damages against the company formerly known as 23andMe over the 2023 breach, though non-monetary remedies may still be sought. The ruling requires the state to dismiss or amend its May 28 lawsuit to remove claims for monetary relief.
In 2023, a breach at 23andMe exposed genetic and other personal information belonging to an estimated 6.9 million customers. Authorities later said the incident was tied to cybersecurity failures including weak protections against credential-based attacks and inadequate monitoring.
On May 28, California Attorney General Rob Bonta sued the company formerly known as 23andMe, seeking potentially millions of dollars in civil fines over the 2023 breach. The suit was later affected by the company's bankruptcy proceedings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
16 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcehipaajournal.com
Open sourceag.ny.gov
Open sourcebusinessinsurance.com
Open source23andme.org
Open sourceaepd.es
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.