twiw-horizontal-trans-150h
Is there a story you think we should be covering? Have a tip on something we should look at?
Contact Us

23andMe Settles with 42 States for 2023 Data Breach

By Tom Marino | July 14, 2026
Last Updated: July 14, 2026

BOSTON – Attorney General Andrea Joy Campbell announced on Tuesday, July 14, that Massachusetts joined 42 other states in announcing a settlement with direct-to-consumer genetic testing company 23andMe to resolve allegations related to a 2023 data breach.

According to the settlement, 23andMe pays $18 million, including $387,218 to Massachusetts. The company filed for bankruptcy in 2025, but the settlement funds will be paid out immediately from available bankruptcy funds. The company also agreed to pay nearly $47 million in a class-action settlement in the bankruptcy case to provide relief to those who submitted claims.

“Consumers have a right to expect that the companies entrusted with their most personal information will protect it. This settlement reinforces security requirements for the remaining 23andMe data, maintains consumers’ right to delete their information, and makes clear that companies cannot cut corners when it comes to data privacy,” said Campbell. “I will continue to hold companies accountable when they fail to protect consumers and their sensitive information.”

In October 2023, 23andMe announced it discovered a data breach that affected 6.9 million consumers, including at least 136,761 in Massachusetts. The breach exposed a range of data about the company’s customers, including in some cases genetic ancestry information. Some data appeared for sale on the “dark web.”

A multi-state investigation formed by attorneys general found 23andMe engaged in unreasonable data security practices, including, but not limited to:

  • Failing to employ safeguards against similar attacks, including by comparing passwords against lists of known breached passwords or by requiring multifactor authentication;
  • Failing to implement appropriate limitations on the number of login attempts over time;
  • Failing to implement logging and monitoring or other tools likely to detect a data breach;
  • Failing to appropriately investigate or address unusual login patterns, including, for example, massive spikes in login attempts;
  • Failing to remediate known vulnerabilities; and
  • Failing to properly review and test design features.

The other states where the attorney general joined the settlement are Alaska, Alabama, Arkansas, Arizona, Colorado, Connecticut, Delaware, the District of Columbia, Florida, Georgia, Idaho, Iowa, Illinois, Indiana, Kansas, Kentucky, Louisiana, Maryland, Maine, Michigan, Minnesota, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Vermont, Washington, Wisconsin, and West Virginia.

Follow us on The016.com, the social network for Worcester and you!