← All news

breach

23andMe Pays $18M Over Breach It Blamed on Customers

2026-07-17

23andMe, now trading as Chrome Holding Co., has agreed to pay $18 million to settle claims brought by 43 US attorneys general over the 2023 breach that exposed the genetic data of 6.9 million people. New York Attorney General Letitia James led the coalition, and the findings are not kind.

What actually happened

The original incident was a credential-stuffing attack. That's the one where attackers take username and password pairs leaked from other breaches and try them, at scale, against a target site. It works depressingly often because people reuse passwords.

The attack against 23andMe ran from April to September 2023 and went unnoticed for five months. Investigators concluded the company had:

  • No password blocklisting to reject known-compromised credentials
  • No multifactor authentication
  • Weak rate limiting on login attempts
  • No meaningful intrusion detection
  • Known vulnerabilities left unpatched
  • Unusual login activity that was flagged internally and then ignored

The stolen ancestry data ended up for sale on the dark web, with samples leaked as proof of the goods.

The response made things worse

What stung regulators almost as much as the security failures was how 23andMe handled the aftermath. The company first denied a breach had occurred at all. When that position became untenable, it pointed the finger at customers for reusing passwords, as if the absence of MFA and rate limiting on a genetic-data platform were a customer problem.

It then quietly changed its Terms of Use to make it harder to sue the company, a move that regulators tend to notice.

The financial trail from there is worth reading in one go:

  • A separate $30 million class-action settlement in 2024
  • A £2.31 million fine from the UK's Information Commissioner's Office
  • Chapter 11 bankruptcy in March 2025
  • Co-founder Anne Wojcicki buying the assets back through a nonprofit for $305 million in July 2025
  • And now the $18 million multi-state settlement

What the settlement demands

The rebuilt entity has been told to stand up a data security advisory board, run proper risk analysis, and continue letting customers delete their data. In other words, the basics. Password blocklisting, MFA, rate limiting, log review, patching. The kind of controls that cost a rounding error compared to $18 million, provided they are in place before the credential-stuffing scripts arrive rather than after.

The uncomfortable bit

Credential stuffing is not a sophisticated attack. It is one of the most predictable threats a consumer-facing platform will face, and the defences against it are well understood and cheap. A company holding the genetic records of nearly seven million people had none of them switched on.

The regulators noticed. The customers noticed. The dark-web buyers definitely noticed. Everyone, it turns out, was paying more attention than 23andMe was.

23andMe Pays $18M Over Breach It Blamed on Customers | RiskSense