A bipartisan coalition of 43 state attorneys general has secured an $18 million settlement with genetic testing company 23andMe following its failure to protect customer data in a 2023 credential-stuffing attack that exposed the personal and genetic information of approximately 6.9 million users. The agreement, announced by New York Attorney General Letitia James, resolves a multistate investigation into the company’s security practices and imposes new cybersecurity requirements on the organization now managing one of the world’s largest consumer DNA databases.
How the 2023 23andMe Breach Unfolded
The October 2023 incident began when attackers used usernames and passwords stolen from unrelated breaches to access 23andMe accounts through a credential-stuffing attack. Because the company had not enabled multifactor authentication at the time, the attackers gained direct access to accounts and then exploited the DNA Relatives feature to collect profile information linked to those accounts, dramatically amplifying the number of affected individuals. Data belonging to approximately 6.9 million people was ultimately accessed, with some records later appearing for sale on dark web marketplaces. The breach affected 305,245 New York residents alone.
Security Failures Identified by Investigators
The multistate investigation catalogued a series of basic security controls that 23andMe had failed to implement. According to the attorneys general, the company did not screen passwords against databases of known breached credentials, did not require multifactor authentication for customer accounts, failed to adequately monitor for suspicious login activity, did not investigate unusual authentication patterns, and neglected to promptly remediate known vulnerabilities.
Investigators also criticized the company’s incident response, noting that it took months to identify the breach after stolen data had already become publicly available on hacker forums. 23andMe initially disputed reports of the breach before later confirming the incident.
What the $18 Million Settlement Requires
Under the settlement, 23andMe will pay $18 million to participating states, with more than $705,000 allocated to New York. Beyond the financial penalty, the agreement mandates enhanced security measures including comprehensive risk assessments, the establishment of a dedicated data security advisory board, and continued support for customers who choose to delete their personal and genetic information.
The consent decree follows a turbulent period for the company. 23andMe filed for bankruptcy in March 2025, prompting legal action from multiple states over the future of its genetic database. The company’s customer data was ultimately transferred to TTAM Research, a nonprofit founded by former CEO Anne Wojcicki that has since been renamed the 23andMe Research Institute. That new organization will also be subject to the settlement’s security requirements.
What Affected Users Should Do Now
Anyone who has used 23andMe should take several steps immediately. Enable multifactor authentication on any account still active to prevent credential-stuffing attacks. Use unique, strong passwords that have not appeared in known data breaches — a zero-knowledge password manager can help generate and store these credentials securely. Monitor accounts and credit reports for suspicious activity, as exposed personal information can be used in targeted phishing or identity theft attempts.
For users who no longer want their genetic data retained, 23andMe continues to offer the option to delete personal and genetic information. Given the sensitive nature of DNA data and the history of security failures at the company, this is a step every current customer should carefully consider. The core lesson of this breach remains unchanged: basic security controls such as multifactor authentication and proactive credential monitoring are not optional for companies handling sensitive personal data, especially genetic information that cannot be changed once exposed.