breach
23andMe pays $18M after blaming customers for its own breach
2026-07-16

Forty-two state attorneys general have landed an $18 million settlement with 23andMe over the 2023 breach that exposed data belonging to 6.9 million people, genetic ancestry information included. The company didn't spot the intrusion at the time. It only found out months later, when stolen records started surfacing on the dark web.
The investigation that followed was brutal reading. New York Attorney General Letitia James described a sequence that will feel familiar to anyone who has watched a breach response go sideways: 23andMe first denied there had been a breach, then confirmed there had been, then pointed at customers for reusing passwords across sites.
What investigators actually found
The password reuse argument might have been more persuasive if the company had done any of the things you'd expect a business holding genetic data to do. It hadn't.
- No defences against credential stuffing, the technique attackers used.
- No meaningful intrusion prevention.
- No logging or monitoring worth mentioning.
- A backlog of known vulnerabilities left unpatched.
- Unusual login patterns that went unexamined.
- New features shipped without security testing.
Credential stuffing works because password reuse is genuinely rampant. That part of 23andMe's defence isn't wrong. It's just that the technique is well-known, cheap to defend against with basic rate limiting and anomaly detection, and the exact sort of attack you'd expect a company sitting on millions of genetic profiles to have thought about.
Where the money goes
The $18 million settlement is separate from a $47 million victims' fund approved by a Missouri bankruptcy court in June. 23andMe filed for bankruptcy in March, and CEO Anne Wojcicki set up the 23andMe Research Institute, a nonprofit, in May to absorb the assets. The Research Institute paid $305 million for those assets in July, genetic data included.
As part of the settlement, the Institute has to run new risk assessments and stand up a dedicated board to oversee data security. Customers keep the right to delete their data and have their genetic samples destroyed at any time. The Institute has committed to honouring the original privacy policy: no sharing with employers, insurers or law enforcement without a court order. De-identified data will still be sold on for biomedical research, as it was before.
The bit that stings
Most stolen data has a shelf life. Card numbers get reissued. Passwords get rotated. Even social security numbers, painful as they are to change, aren't a life sentence.
Genetic data is different. It doesn't expire. You can't rotate your ancestry. Whatever was taken in 2023 is out there for as long as anyone cares to keep a copy of it, and it belongs to 6.9 million people who thought they were paying for a novelty saliva test.
Which makes the absence of logging, monitoring and patching feel especially expensive. Not the $18 million kind of expensive. The kind that doesn't get any cheaper with time.