A coalition of 42 attorneys general has reached an $18 million settlement with the bankruptcy trustee for 23andMe over a 2023 cyberattack that exposed the personal and genetic information of 6.9 million customers worldwide.
It is yet another reminder of the perils when digital personal health information, including diagnostic test data, is not fully guarded against cyberattacks.
The agreement resolves allegations that the direct-to-consumer genetic testing company failed to use reasonable safeguards to protect highly sensitive customer data.
Massachusetts Attorney General Andrea Joy Campbell announced the settlement, noting that the state will receive $387,218. The funds will be paid immediately from money available through 23andMe’s bankruptcy estate.
23andMe also agreed to a separate $46.75 million class-action settlement for affected US consumers who submitted claims by Feb. 17, 2026.
“Consumers have a right to expect that the companies entrusted with their most personal information will protect it,” Campbell said in a statement.
She added that the settlement strengthens security requirements for the remaining 23andMe data, preserves consumers’ ability to delete their information, and demonstrates that companies cannot cut corners when protecting sensitive data.
Consequences are significant for health information data breaches
For clinical laboratories, pathology groups, biobanks, and diagnostics companies, the case illustrates the unusually high consequences associated with genomic-data breaches.
Organizations that collect or retain genomic data may therefore face increasing scrutiny over access controls, cybersecurity monitoring, vendor oversight, breach response, and policies governing patients’ ability to delete their information.
As Dark Daily reported in March 2025, 23andMe’s bankruptcy had already raised questions about whether genetic information could be transferred or sold as a company asset. The article urged clinical laboratory leaders to examine what would happen to patient genetic data during a bankruptcy, acquisition, or merger, including whether patients could request deletion before ownership changed. The new settlement and sale requirements reinforce those concerns by preserving deletion rights and imposing additional privacy and security obligations on the purchaser of 23andMe’s data.
The settlement also echoes warnings from cybersecurity experts interviewed by The Dark Report in May 2026. They explained that modern ransomware attacks often begin with an unnoticed intrusion, followed by a prolonged period during which criminals study systems, steal data, and identify the organization’s most critical operations before deploying malware or demanding payment. For clinical laboratories, that means unusual login activity or compromised credentials should be treated as potential early signs of a larger attack—not merely isolated information technology problems.
The settlement should serve as a warning to clinical laboratories and diagnostics companies that cybersecurity is not simply an information technology concern, but also a core compliance, legal, and patient-trust issue.
Credential-stuffing attack exposed security failures
23andMe disclosed the breach in October 2023.
The incident involved credential stuffing, in which attackers use usernames and passwords stolen in previous breaches to attempt access to accounts on other platforms.
Once attackers gained access to individual accounts, certain 23andMe features allowed them to obtain information connected to millions of additional customer profiles.
The exposed information included genetic ancestry data and other personal details. Portions of the stolen data were later offered for sale on the dark web.
According to the attorneys general, 23andMe learned of the attack months after some affected information had already become publicly available. The company initially denied that a breach had occurred and later blamed consumers’ password practices, despite knowing that credentials associated with some customers may have been compromised through an earlier breach involving former partner MyHeritage. Investigators identified several alleged security weaknesses.
These included failing to require multifactor authentication, compare passwords against lists of known compromised credentials, sufficiently limit repeated login attempts, and adequately monitor unusual account activity.
The company also allegedly failed to respond appropriately to massive spikes in login attempts, remediate known vulnerabilities, and properly review and test certain design features.
This article was created with the assistance of Generative AI and has undergone editorial review before publishing.





