Court Rules
All enforcement actions
SettlementHigh RiskMultistate

Multistate Settlement of Bankruptcy Claims Against 23andMe Over Genetic Data Breach

23andMeJuly 14, 2026Oregon Attorney General

Penalty Amount

$18,000,000

Consumers Affected

6,900,000

Summary

A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.

Remedy

The settlement includes $18 million in monetary recovery from bankruptcy funds, enhanced data security requirements for the successor entity (23andMe Research Institute), mandatory risk analysis, establishment of an Advisory Board, binding compliance with comprehensive privacy laws, and continued consumer deletion rights.

Monetary PenaltyInjunctionCompliance ProgramData DeletionReporting Requirements

Contract Impact

In-house legal teams should review vendor agreements with data processors handling sensitive personal information, particularly genetic or biometric data. Key clauses to examine include: data security obligations (requiring multifactor authentication, rate limiting, and credential stuffing protections), breach notification timelines and responsibilities, data retention and deletion provisions, and liability allocation for security failures. Customer-facing terms of service and privacy policies should be updated to clearly describe data security measures and consumer rights regarding data deletion. Employee agreements involving access to sensitive data should include confidentiality and security training requirements.

Contract Search Terms

data breach notificationcredential stuffing safeguardsmultifactor authenticationgenetic databiometric datadata security practicespassword reuserate limitingintrusion preventionconsumer deletion rights

Laws Cited

State consumer protection lawsState data breach notification laws

Violation Types

Entity Details

Entity

23andMe

Industry

Technology

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"23andMe"
Fine Amount
"$18 million"
Consumers Affected
"6.9 million customers"
Violation Types
"unreasonable data security practices"
Is Multistate
"a coalition of 41 other attorneys general"
Remedy Types
"enhanced data security requirements"

Related Enforcement Actions

VA

23andMe

$663K

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

TX

23andMe

$150.0M

Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.

NY

23andMe

$18.0M

New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.

CT

23andMe

$18.0M

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

CT

23andMe

Connecticut Attorney General William Tong submitted testimony in support of genetic privacy legislation that would grant residents exclusive control over their DNA and genetic data. The legislation is inspired by his office's investigation into 23andMe's data breach affecting over six million customers and the company's subsequent bankruptcy. The bill requires express consent for DNA use, imposes security measures, and prohibits marketing use of DNA.

TX

23andMe

Texas Attorney General Ken Paxton filed a lawsuit in the 23andMe bankruptcy case to prevent the sale of Texans' genetic data without proper consent. The action seeks to confirm Texans' property rights over their genetic information under the Texas Data Privacy and Security Act and the Texas Direct-to-Consumer Genetic Testing Act. The AG argues that 23andMe's proposed asset sale would violate Texas law requiring separate express consent for disclosure of genetic information.