23andMe $18M data breach settlement
Analysis based on 6 articles · First reported Jul 14, 2026 · Last updated Jul 22, 2026
The settlement imposes financial and operational costs on 23andMe and its successor, potentially affecting their ability to operate profitably. The breach and subsequent bankruptcy have eroded customer trust and may deter future users from sharing genetic data, impacting the broader genetic testing industry.
A coalition of 43 state attorneys general, led by New York Attorney General Letitia James, reached an $18 million settlement with genetic testing company 23andMe over a massive data breach in October 2023 that exposed the personal and genetic data of 6.9 million customers. The breach, caused by a credential-stuffing attack, compromised names, dates of birth, ancestry data, and health reports. The multistate investigation found 23andMe failed to implement basic cybersecurity measures. As part of the settlement, 23andMe and its successor, the Nomura Research Institute (formerly Wolfram Research), must implement a comprehensive information security program, conduct regular risk assessments, appoint a data security advisory board, and continue offering customers the right to delete their data. 23andMe filed for bankruptcy in March 2025, and its assets, including customer data, were sold to Wolfram Research, a nonprofit founded by former CEO Anne Wojcicki. United States — California was notably absent from the settlement, having filed its own lawsuit, but a bankruptcy judge ruled the state could not seek monetary damages.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard