Genetic testing company 23andMe, now part of Chrome Holding Co., has agreed to pay $18 million to settle allegations from 43 state attorneys general regarding failures in protecting customer genetic data.
In October 2023, 23andMe reported a significant data breach caused by a credential stuffing attack that remained undetected from April to September 2023.
During this breach, attackers compromised data of 6.9 million customers, including sensitive genetic ancestry information. This data was subsequently sold on the dark web and the attackers leaked millions of genetic profiles as proof of its legitimacy.
New York Attorney General Letitia James announced that a multi-state investigation revealed 23andMe lacked basic security measures against credential-based cyberattacks. The company failed to implement essential safeguards including password blocklists and multi-factor authentication, as well as adequate rate limiting and intrusion prevention systems.
Investigators noted that 23andMe did not adequately respond to unusual login activity or fix known vulnerabilities. Initially, the company denied a breach occurred but later attributed it to customers’ weak account and password practices.
The settlement mandates new security requirements, including a data security advisory board, risk analysis protocols, and consumers’ continued right to delete their data.
“Companies have a duty to safeguard customers’ personal information, yet 23andMe has endangered millions with its inadequate security practices,” James stated.
“Customers entrusted 23andMe with sensitive genetic data only to find it for sale in dark web markets. Our coalition’s actions ensure 23andMe pays the consequences for breaking the law, with strict regulations now in effect to protect consumers.”
Class Actions, Fines, and Settlements
The 2023 breach sparked multiple class action lawsuits, prompting 23andMe to amend its terms of service in November to make litigation more challenging, asserting that the amendments simplified arbitration.
In September 2024, 23andMe also agreed to pay $30 million to resolve a class action lawsuit linked to the data breach.
After years of financial struggles, 23andMe entered Chapter 11 bankruptcy protection in March 2025 and announced plans to sell its assets, leading to further lawsuits from Attorney General James and the coalition.
In June 2025, James, alongside 27 other attorneys general, filed a lawsuit to safeguard customer genetic data during bankruptcy proceedings. That month, the UK Information Commissioner’s Office fined 23andMe £2.31 million ($3.12 million) for “serious security flaws” associated with the 2023 data breach.
Subsequently, in July 2025, the nonprofit TTAM Research Institute (now 23andMe Research Institute, co-founded by Anne Wojcicki) completed its acquisition of 23andMe, agreeing to pay $305 million for all its assets.
Security teams only document 54% of successful attacks and issue warnings for just 14%. The remaining attacks move undetected through systems.
Picus’ whitepaper illustrates methods to test your SIEM and EDR rules in breach simulations to ensure threat detection.
Source: www.bleepingcomputer.com




