
A bipartisan coalition of 43 state attorneys general — representing all 50 states and Washington D.C. — has secured an $18 million settlement from genetic testing company 23andMe following a 2023 data breach that exposed the sensitive information of 6.9 million customers worldwide. The breach compromised genetic ancestry data that some victims found published for sale on the dark web. The settlement was announced on July 14, 2026, and the money will be paid out immediately from 23andMe’s bankruptcy estate.
Investigators found that 23andMe had failed to put basic security protections in place — things like preventing users from setting passwords that had already been leaked online, requiring two-factor authentication, or monitoring for intrusions. As part of the settlement, 23andMe (now reorganized as 23andMe Research Institute after a nonprofit acquisition) must maintain a data security advisory board, conduct regular risk analyses, and continue giving customers the right to request deletion of their genetic information. If you had a 23andMe account and want to exercise that right, you can submit a deletion request directly through the company’s website.
