42 Attorneys General Win $18 Million From 23andMe Over Genetic Data Breach as Bankruptcy Court Blocks California's Damages Claim
A 42-attorney-general coalition settled bankruptcy claims against 23andMe for $18 million over the 2023 breach of 6.9 million genetic profiles, days after a court barred California from separately pursuing damages.
Overview
A coalition of 42 attorneys general has settled bankruptcy claims against the direct-to-consumer genetic testing company 23andMe, resolving allegations stemming from a 2023 data breach that compromised the genetic data of 6.9 million customers worldwide, according to Colorado Attorney General Phil Weiser. The states will recover $18 million, paid immediately out of the bankruptcy estate’s available funds.
The multistate deal, announced in mid-July, landed days after a separate setback for California, whose attorney general was barred by a bankruptcy court from pursuing monetary damages over the same breach, Insurance Journal reported.
A $150 million claim, $18 million in cash
The settlement gives the states $150 million in allowed claims, but because the bankruptcy estate holds finite funds and faces numerous other claims, recovery is limited to $18 million, paid out of available bankruptcy funds immediately, according to the Delaware Department of Justice. Delaware said the company announced in October 2023 that 6.9 million consumers were affected.
The agreement also carries forward security obligations attached to the earlier sale of 23andMe’s assets. The buyer agreed to enhanced data security requirements, appropriate risk analysis, the addition of an advisory board, being bound by comprehensive privacy laws without exception, and continuing to offer consumers deletion rights, according to Weiser’s office. Those assets, including 23andMe’s consumer data, were sold to TTAM Research Institute, a non-profit formed by 23andMe founder and former CEO Anne Wojcicki.
“Because of today’s settlement with 23andMe, Coloradans’ data will be in safer hands and consumers will keep their rights over their data,” Weiser said.
“Today’s results show that my office will continue to hold companies like 23andMe accountable when they fail to safeguard sensitive personal data collected from Delawareans,” said Attorney General Kathy Jennings.
California blocked from separate damages
Days earlier, a bankruptcy court checked California’s parallel effort to extract civil penalties. On July 10, U.S. Bankruptcy Judge Brian Walsh in St. Louis ruled that California cannot pursue monetary damages against Chrome Holding Co., the 23andMe successor, and its affiliate, though the state may still seek non-monetary remedies, Insurance Journal reported. Walsh gave California 14 days to either dismiss the lawsuit it filed on May 28 in San Francisco Superior Court or amend the complaint to eliminate its claims for monetary relief.
California Attorney General Rob Bonta had accused 23andMe of ignoring warnings that its systems were compromised and downplaying the breach’s severity, according to Insurance Journal. “Because the state was a party to the Chapter 11 case and was given a fair chance to challenge this court’s subject-matter jurisdiction, the state cannot challenge it now,” Walsh wrote.
The law firm Paul, Weiss, which characterized the outcome as a win for the 23andMe debtors, said the court “granted the motion in relevant part, finding the plan barred California from pursuing monetary relief against the debtors in state court, and required California to dismiss its suit entirely or amend the complaint to dismiss all claims for monetary relief against the debtors,” in a client note.
The breach behind the case
The underlying intrusion began on April 29, 2023, and continued for approximately five months, as a threat actor fed usernames and passwords stolen from other websites into 23andMe’s login page until matches were found, a technique known as credential stuffing, according to Security.org. The company did not require two-factor authentication at the time.
Attackers directly accessed roughly 14,000 accounts, less than 0.1 percent of 23andMe’s roughly 14 million customers, then used those accounts to scrape the interconnected DNA Relatives profiles, ultimately pulling data from approximately 5.5 million additional users, Security.org reported. Some of the stolen records were curated by ethnicity: one batch was advertised as a list of Ashkenazi Jewish users and another as a list of people of Chinese descent.
Colorado investigators tied the intrusion in part to 23andMe’s partnership with MyHeritage, which had itself been compromised years earlier, exposing credentials shared between the two websites, Weiser’s office said.
Payouts and what remains
Separately, on July 7, Judge Walsh approved a $46.75 million class-action settlement for consumers affected by the breach, calling it fair and equitable, Insurance Journal reported. The breach affected almost 7 million users, roughly half of the company’s customers, according to Gizmodo. Affected U.S. consumers had to submit claims by February 17, 2026, the Delaware Department of Justice said.
TTAM bought 23andMe’s assets for $305 million, Insurance Journal reported.
What we don’t know
Neither settlement retrieves genetic data already copied and advertised online, and the injunctive terms reach only the records that remain under the successor’s control. The $18 million in cash is a fraction of the $150 million at which the states’ claims were valued, a gap the Delaware Department of Justice attributed to the estate’s finite funds. It also remains unresolved whether California will drop its suit entirely or refile within the court’s 14-day window for the non-monetary remedies the judge left open.