Court Rules
All enforcement actions
SettlementCritical RiskMultistate

New York AG Secures $18 Million from 23andMe for Data Breach Exposing Genetic Data

23andMeJuly 14, 2026New York Attorney General

Penalty Amount

$18,000,000

Consumers Affected

6,900,000

Summary

New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.

Remedy

23andMe will pay $18 million, with over $705,000 to New York. The settlement requires 23andMe Research Institute (formerly TTAM Research) to implement new data security measures including appropriate risk analysis, an Advisory Board on data security, and continuing to offer consumers the right to delete their information.

Monetary PenaltyInjunctionCompliance ProgramAudit RequirementData DeletionReporting Requirements

Contract Impact

In-house legal teams should review vendor agreements with any company handling sensitive personal data (especially genetic, biometric, or health data) for data security obligations, breach notification timelines, and post-bankruptcy data handling provisions. Key clauses to examine include: (1) data security requirements (e.g., multifactor authentication, password policies, intrusion detection); (2) breach notification obligations (timing, content, and responsibility for costs); (3) data deletion rights upon contract termination or consumer request; (4) change-of-control or bankruptcy provisions that restrict sale or transfer of personal data; and (5) indemnification for security failures. Customer-facing privacy policies and consent forms should also be reviewed to ensure they clearly describe data protection measures and breach response procedures.

Contract Search Terms

data breach notificationsecurity failuregenetic datamultifactor authenticationpassword blocklistrate limitingintrusion preventiondata deletion rightbankruptcy data saleconsumer genetic information

Laws Cited

New York General Business LawState data breach notification laws

Violation Types

Entity Details

Entity

23andMe

Industry

Technology

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"23andMe"
Fine Amount
"$18 million"
Violation Types
"data breach affecting 6.9 million consumers"
Violation Types
"failed to take critical security measures"
Violation Types
"The company first denied a breach and then, once it confirmed the breach, blamed costumers"
Consumers Affected
"6.9 million consumers"

Related Enforcement Actions

VA

23andMe

$663K

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

TX

23andMe

$150.0M

Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.

CT

23andMe

$18.0M

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

OR

23andMe

$18.0M

A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.

CT

23andMe

Connecticut Attorney General William Tong submitted testimony in support of genetic privacy legislation that would grant residents exclusive control over their DNA and genetic data. The legislation is inspired by his office's investigation into 23andMe's data breach affecting over six million customers and the company's subsequent bankruptcy. The bill requires express consent for DNA use, imposes security measures, and prohibits marketing use of DNA.

TX

23andMe

Texas Attorney General Ken Paxton filed a lawsuit in the 23andMe bankruptcy case to prevent the sale of Texans' genetic data without proper consent. The action seeks to confirm Texans' property rights over their genetic information under the Texas Data Privacy and Security Act and the Texas Direct-to-Consumer Genetic Testing Act. The AG argues that 23andMe's proposed asset sale would violate Texas law requiring separate express consent for disclosure of genetic information.