A coalition of 42 state attorneys general has agreed to a $18 million settlement with 23andMe (now Chrome Holding Co.) to resolve alleged cybersecurity failures that led to an October 2023 data breach affecting 6.9 million of its customers. The settlement also includes a commitment to implement new data security measures to better secure consumer data and prevent further data breaches.
The 23andMe data breach occurred as a result of credential stuffing, which is where credentials obtained in a data breach at one or more companies are used to try to gain access to accounts on an unrelated platform. These attacks can only succeed if individuals reuse the same credentials across multiple accounts. When the credential stuffing campaign was discovered, 23andMe maintained that there had not been a breach, and that the compromised accounts were the result of customers’ poor security practices.
While 23andMe customers took risks by reusing their credentials on the 23andMe site, the multistate investigation found that 23andMe was at fault as the company lacked basic cybersecurity measures for preventing credential-based attacks. For instance, 23andMe did not compare users’ passwords against blocklists of known breached passwords, did not require multifactor authentication, and did not have rate limiting or intrusion prevention measures in place. Further, there was insufficient logging and monitoring, which allowed the credential-stuffing campaign to go unnoticed for five months between April 2023 and September 2023, and a failure to investigate and address unusual login patterns, such as a massive spike in login attempts indicative of a credential stuffing campaign. The investigation also identified a failure to fix known vulnerabilities and properly review and test design features of its platform.
23andMe filed for bankruptcy protection in March 2025, and the company’s data was sold to TTAM Research, a company formed by 23andMe founder and former CEO, Anne Wojcicki. The coalition sued 23andMe during the company’s bankruptcy, and the new data security requirements apply to TTAM, which is now registered as 23andMe Research Institute. The $18 million settlement will be paid to the participating states, with New York due to receive more than $705,000.
“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” said Attorney General James. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law, and strict rules will be put in place to protect their customers.”
23andMe has previously agreed to pay $46.75 million as compensation to victims of the data breach, and has previously been fined by data protection watchdogs in Spain ($2.75M) and the United Kingdom ($3.1M) over the data breach. California did not participate in the multistate action, having filed its own lawsuit; however, a bankruptcy judge ruled this month that the state cannot seek monetary relief due to its Chapter 11 reorganization plan.
The post 23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit appeared first on The HIPAA Journal.


