23andMe settles 2023 data breach for $18 million

A multistate investigation into the 2023 23andMe breach results in an $18 million settlement and new cybersecurity mandates.

By Central
The settlement requires 23andMe to implement multifactor authentication and other security controls after exposing 6.9 million users' data.
Highlights
  • The 2023 breach used credential stuffing and exposed the genetic data of approximately 6.9 million users.
  • 23andMe failed to implement basic security controls like multifactor authentication and password screening.
  • The $18 million settlement imposes enhanced cybersecurity requirements and a dedicated data security advisory board.

A bipartisan coalition of 43 state attorneys general has secured an $18 million settlement with genetic testing company 23andMe following its failure to protect customer data in a 2023 credential-stuffing attack that exposed the personal and genetic information of approximately 6.9 million users. The agreement, announced by New York Attorney General Letitia James, resolves a multistate investigation into the company’s security practices and imposes new cybersecurity requirements on the organization now managing one of the world’s largest consumer DNA databases.

How the 2023 23andMe Breach Unfolded

The October 2023 incident began when attackers used usernames and passwords stolen from unrelated breaches to access 23andMe accounts through a credential-stuffing attack. Because the company had not enabled multifactor authentication at the time, the attackers gained direct access to accounts and then exploited the DNA Relatives feature to collect profile information linked to those accounts, dramatically amplifying the number of affected individuals. Data belonging to approximately 6.9 million people was ultimately accessed, with some records later appearing for sale on dark web marketplaces. The breach affected 305,245 New York residents alone.

Security Failures Identified by Investigators

The multistate investigation catalogued a series of basic security controls that 23andMe had failed to implement. According to the attorneys general, the company did not screen passwords against databases of known breached credentials, did not require multifactor authentication for customer accounts, failed to adequately monitor for suspicious login activity, did not investigate unusual authentication patterns, and neglected to promptly remediate known vulnerabilities.

Investigators also criticized the company’s incident response, noting that it took months to identify the breach after stolen data had already become publicly available on hacker forums. 23andMe initially disputed reports of the breach before later confirming the incident.

What the $18 Million Settlement Requires

Under the settlement, 23andMe will pay $18 million to participating states, with more than $705,000 allocated to New York. Beyond the financial penalty, the agreement mandates enhanced security measures including comprehensive risk assessments, the establishment of a dedicated data security advisory board, and continued support for customers who choose to delete their personal and genetic information.

The consent decree follows a turbulent period for the company. 23andMe filed for bankruptcy in March 2025, prompting legal action from multiple states over the future of its genetic database. The company’s customer data was ultimately transferred to TTAM Research, a nonprofit founded by former CEO Anne Wojcicki that has since been renamed the 23andMe Research Institute. That new organization will also be subject to the settlement’s security requirements.

What Affected Users Should Do Now

Anyone who has used 23andMe should take several steps immediately. Enable multifactor authentication on any account still active to prevent credential-stuffing attacks. Use unique, strong passwords that have not appeared in known data breaches — a zero-knowledge password manager can help generate and store these credentials securely. Monitor accounts and credit reports for suspicious activity, as exposed personal information can be used in targeted phishing or identity theft attempts.

For users who no longer want their genetic data retained, 23andMe continues to offer the option to delete personal and genetic information. Given the sensitive nature of DNA data and the history of security failures at the company, this is a step every current customer should carefully consider. The core lesson of this breach remains unchanged: basic security controls such as multifactor authentication and proactive credential monitoring are not optional for companies handling sensitive personal data, especially genetic information that cannot be changed once exposed.

Share This Article