What's Happening?
Genetic testing company 23andMe has reached an $18 million settlement with a coalition of 42 U.S. attorneys general following a significant data breach in 2023. The breach, which affected over six million individuals, involved unauthorized access to customer
profile information through a credential stuffing attack. This attack exploited weak password management and the absence of multi-factor authentication among users. As part of the settlement, 23andMe is required to implement new data protection measures, including risk analysis, the establishment of an Advisory Board on data security, and offering consumers the right to delete their information. Additionally, 23andMe will pay over $705,000 to New York as part of the settlement. The company had previously filed for bankruptcy protection in March 2025, and its customer data was sold to TTAM Research, a non-profit formed by 23andMe's founder and former CEO Anne Wojcicki.
Why It's Important?
The settlement underscores the critical importance of robust cybersecurity measures in protecting sensitive personal data, particularly in the genetic testing industry. The breach exposed vulnerabilities in 23andMe's security practices, highlighting the risks associated with inadequate password management and the lack of multi-factor authentication. The new security mandates aim to prevent future breaches and restore consumer trust. This case also illustrates the legal and financial repercussions companies can face when failing to protect customer data, as seen in the additional fines imposed by international regulators. The outcome serves as a cautionary tale for other companies handling sensitive information, emphasizing the need for comprehensive data protection strategies.
What's Next?
Following the settlement, 23andMe is expected to implement the agreed-upon security measures to enhance data protection. The company will need to work closely with TTAM Research to ensure compliance with the new requirements. Additionally, the legal proceedings related to the breach may continue, as California has been given 14 days to amend its lawsuit against 23andMe. The case may also influence future regulatory actions and industry standards for data security, prompting other companies to reassess their cybersecurity practices to avoid similar breaches and legal challenges.













