The $18M settlement between 23andMe and 43 state attorneys general represents a landmark genetic data privacy enforcement, but the security mandates imposed on the company’s new operator may prove more consequential than the monetary penalty. The agreement resolves claims that the testing firm neglected basic authentication controls before attackers compromised roughly 7 million customer profiles through credential stuffing in 2023.
Security experts point to the settlement’s structural requirements as the significant precedent. TTAM Research, the nonprofit that acquired 23andMe’s assets after its March 2025 bankruptcy, must now conduct enterprise risk analyses, convene a data security advisory board, and honor customer data deletion rights. These ongoing obligations extend beyond the typical monetary remedy and bind the successor organization to specific privacy practices.
The breach itself followed a familiar attack pattern. Hackers used credentials stolen from other services to access 23andMe accounts that had reused passwords, then scraped ancestry and health-related genetic data from connected family tree profiles. The stolen information later circulated on dark web forums. For healthcare organizations handling genetic data, the case reinforces that credential stuffing protections and rate limiting are not optional controls when personal genomic information is at stake.
California’s separate lawsuit adds a wrinkle. A bankruptcy judge ruled in July that the state cannot collect damages from the reorganized entity, creating a potential divide between state and federal enforcement powers in bankruptcy proceedings. Texas, New York, Illinois, and Massachusetts led the multistate coalition.
The $18M comes from available bankruptcy funds and will be distributed to participating states. A separate $46.75M class action settlement for affected customers received court approval in January 2026.
