23andMe Settles 2023 Data Breach for $18 Million — 6.9 Million Customers Had Genetic Data Stolen

There is something uniquely unsettling about a genetic testing company getting hacked. A credit card number can be canceled and reissued. DNA cannot. That uncomfortable reality sits at the center of a new settlement between 23andMe and 43 state attorneys general, announced July 14 by New York Attorney General Letitia James.

23andMe has agreed to pay $18 million to resolve investigations into an October 2023 data breach that exposed the genetic and personal information of 6.9 million customers.

The attack itself was methodical but not sophisticated. Hackers used credential stuffing — reusing passwords leaked from other sites — to log into roughly 14,000 23andMe accounts. Once inside, they exploited two of the company’s own features: DNA Relatives, which connects users with genetic relatives, and Family Tree, which maps ancestry relationships. Those tools let the attackers pull data from hundreds of thousands of additional accounts beyond the 14,000 they initially compromised. Some of the stolen data was later listed for sale on the dark web.

A joint investigation by the attorneys general found multiple gaps in 23andMe’s security posture. The company did not check whether user passwords had appeared in known credential leaks. It did not require multi-factor authentication. It lacked adequate rate limiting on login attempts, intrusion detection systems, and the kind of logging and monitoring that would have flagged abnormal activity sooner.

Under the settlement, 23andMe must conduct a comprehensive risk assessment and form a data security advisory committee. It must also continue offering customers the ability to delete their personal data on request. The company is required to maintain an information security program specifically designed for the sensitivity of genetic information.

The 2023 breach forced an uncomfortable conversation about how genetic testing companies handle data. Unlike a password or a credit card number, genetic data is permanent — it is directly tied to an individual’s identity and cannot be changed if compromised. That makes the stakes for data protection in this industry higher than a typical database leak.

The $18 million settlement covers 43 participating states. 23andMe did not admit liability as part of the agreement.