23andMe Agrees to New Security Terms in $18M Settlement
Genetic testing firm 23andMe has reached an $18 million settlement with 42 U.S. attorneys general following the 2023 data breach that affected over 6 million users. The deal imposes strict new data protection mandates on the new entity that acquired the bankrupt company's data.
What Happened
23andMe, the well-known genetic testing and ancestry service, is facing the legal consequences of its massive 2023 data breach. The company announced it has reached an $18 million settlement with a coalition of 42 U.S. states, led by New York Attorney General Letitia James. This agreement involves not just a financial penalty but also imposes significant and binding new security requirements on how the company must protect customer data in the future. As part of the settlement, 23andMe will pay over $705,000 to the state of New York alone.
The chain of events began in October 2023, when cybercriminals gained access to the profile information of millions of 23andMe users. Following the breach, the company entered a financial downturn, filing for bankruptcy protection in March 2025. This bankruptcy process raised serious concerns about the future of customer data. Attorney General James and the coalition took legal action, suing 23andMe in June 2025 to protect Americans' personal genetic information during the company's bankruptcy. This legal intervention also included claims related to the data breach investigation.
As a result of the bankruptcy, 23andMe's most valuable asset—its customer data—was sold to TTAM Research, a non-profit organization established by the company's founder and former CEO, Anne Wojcicki. This transfer opened a new chapter for data protection. The current settlement with the coalition of attorneys general directly sets out strict rules that this new entity, TTAM, must follow. The goal is to prevent the repetition of past mistakes and to secure the highly sensitive genetic data. This development sets an important precedent in the world of technology and data security, showing that companies cannot evade their data responsibilities even if they go bankrupt. For more developments and similar incidents, you can follow Data Breach News.
What Data Was Compromised
The cybercriminals targeted user profiles on the 23andMe platform. According to the company's statements and attorney general documents, information from over six million individuals was affected by the breach. The compromised data included extremely personal and sensitive information such as users' ancestry and lineage. This type of genetic and ancestry data can reveal not only an individual's identity but also their family ties, ethnic background, and potential hereditary health conditions. Therefore, the exposure of this data to cybercriminals poses very serious risks, including identity theft, fraud, and even targeted blackmail. The leak of one user's profile information can indirectly endanger their relatives who are linked through DNA matching, making genetic data breaches far more dangerous than other types of breaches. Although a full list of the compromised data has not been publicly shared, the terms "profile information" and "ancestry information" suggest that details like usernames, birth dates, geographic locations, and family connections may have been exposed.
How Did the Attack Happen
From the early days of the breach, 23andMe maintained that the attack was not the result of a direct infiltration of its own systems. According to the company, the incident was carried out using a technique known as "credential stuffing." This method involves cybercriminals using username and password combinations obtained from previous data breaches at other companies to automatically try to log into accounts on different platforms.
The primary reason this type of attack is successful is the habit of many internet users to reuse the same or very similar passwords across different websites and services. Attackers run bots that test lists containing millions of stolen credentials against platforms like 23andMe. If a user has used a password on their 23andMe account that was leaked from another site, the attackers can easily gain access. In its statement at the time of the incident, 23andMe attributed the root cause of the breach to users' poor password management and, specifically, their failure to enable multi-factor authentication (MFA). MFA provides a strong layer of protection against such attacks by requiring a second verification step, such as a code sent to a phone, in addition to the password.
Who Was Affected
Those directly affected by the breach are the more than six million customers who used 23andMe's genetic testing service. These individuals sought to learn about their ancestry, ethnic origins, and genetic predispositions by having their DNA analyzed. However, due to the nature of the credential stuffing attack, the number of indirectly affected individuals could be much higher. Once attackers gain access to an account, they may also be able to access the basic profile information of other users connected through the "DNA Relatives" feature. This means that even people whose accounts were not directly compromised are at risk. The affected individuals are at risk of fraud and targeted cyberattacks because their identities and most personal information—their genetic data—have been exposed.
What You Can Do
This incident once again highlights the importance of individual responsibility in digital security. Here are some steps you can take to prevent your accounts from being affected by similar attacks:
- Password Management: Use unique and complex passwords for every online service. Reusing the same password across multiple sites means that a breach at one site can compromise all your other accounts. Using a password manager can simplify this process.
- Multi-Factor Authentication (MFA): Enable this feature on 23andMe and all other services that offer MFA support. MFA is one of the most effective ways to prevent unauthorized access to your account, even if your password is stolen.
- Right to Delete Data: As part of the settlement, TTAM Research will continue to offer users the right to delete their data. Requesting the deletion of your personal data from a service you no longer use or trust can protect you from potential future breaches.
- Check for Suspicious Activity: Regularly review your accounts for unrecognized login attempts or other suspicious activities.
What the Company Says
When the breach was first disclosed, 23andMe adopted a stance that largely placed the blame on its users. The company's statements at the time emphasized that the attack was not a breach of its own network but was due to users' poor password habits and failure to use MFA. However, the investigation by 42 attorneys general and the resulting $18 million settlement show that companies are expected to take a more proactive role in protecting user data. The new security mandates imposed on TTAM Research, which acquired 23andMe's data, are proof that this responsibility is now legally recognized. The new requirements for TTAM include conducting appropriate risk analyses, establishing an Advisory Board on data security, and continuing to grant users the right to delete their data. This demonstrates that regulators no longer accept user error as a sole excuse and expect higher security standards from companies.
Source
https://www.infosecurity-magazine.com/news/23andme-18m-data-breach-settlement/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.