The 23andMe Settlement: What $150 Million Tells You About Data Breach Accountability

The 23andMe Settlement: What $150 Million Tells You About Data Breach Accountability
Headshot photo of Charlyn Ho, CEO Rikka Law Group | Co-Founder Enzio.ai at Rikka Law
Charlyn Ho
CEO Rikka Law Group | Co-Founder Enzio.ai
July 21, 2026·Insights

In July 2026, a coalition of 42 state attorneys general announced a $150 million settlement with genetic testing company 23andMe over a 2023 data breach that exposed the genetic, health, and personal information of approximately 6.9 million consumers. The settlement is one of the largest state-level data breach resolutions in recent memory, and one of the most consequential, not just for 23andMe, but for any company that collects sensitive personal data and assumes a breach is a manageable risk rather than a preventable one.

What Happened

23andMe suffered a data breach in 2023 that exposed the personal and genetic data of approximately 6.9 million customers. The company's failure to implement adequate safeguards, the core allegation across all 42 state investigations, allowed attackers to access an extraordinary range of sensitive information: genetic ancestry data, health predispositions, family relationship data, and personal identifiers. Connecticut Attorney General William Tong said the company “collected the most sensitive genetic data imaginable from millions of Americans, and they failed to safeguard that data,” a characterization echoed across the coalition of state attorneys general.

23andMe subsequently filed for bankruptcy. As a result, states are limited to recovering approximately $18 million of the $150 million settlement, a recovery rate that reflects the real cost of combining inadequate security with financial insolvency. The bankruptcy court also barred California from pursuing monetary damages against the company, though California's separate civil action continues for other remedies, illustrating how corporate failure can compound the harm to consumers while limiting available remedies. A separate, privately negotiated class action settlement of $46.75 million for breach victims was also approved by a federal bankruptcy judge earlier in July 2026, underscoring how the same underlying security failure produced both regulatory and private liability.

Why Genetic Data Changes the Stakes

Most data breaches involve financial information, login credentials, or contact data, information that is sensitive but, in many cases, recoverable. Genetic data is in a different category. A person can change a password. They cannot change their DNA.

That distinction matters for how regulators and courts treat genetic and biometric information. The GDPR includes genetic data in its list of “special categories” requiring heightened protection. Most U.S. state privacy laws treat genetic and biometric identifiers as sensitive data subject to additional obligations, including stricter consent requirements and tighter restrictions on third-party sharing. A company that collects this information takes on obligations that scale with the sensitivity of the data, and exposure that grows the same way.

The 23andMe case adds enforcement weight to those statutory requirements. Collecting sensitive biological data without adequate security measures is not a compliance gap to remediate. It is a liability with a dollar figure attached.

What This Signals for Any Business Handling Sensitive Data

The size of the coalition, 42 attorneys general, and the scale of the settlement are deliberate signals. State attorneys general are coordinating on data breach enforcement in ways they were not five years ago. The 23andMe settlement follows a visible pattern: regulators are not waiting for federal frameworks to act, and they are treating security failures as consumer protection violations, not merely technical incidents.

The practical takeaway for any company handling sensitive personal data is direct. Adequate safeguards are a legal requirement, not a best practice. Security assessments, access controls, incident response plans, and vendor oversight are not optional features of a privacy program: they are the baseline regulators will examine when something goes wrong. The question every business should be asking now is not whether a breach is possible, but whether its current security posture would survive regulatory scrutiny in the aftermath.

What This Means Going Forward

The 23andMe settlement will not be the last of its kind. As state enforcement coordination continues to mature and the value of sensitive data continues to rise, the consequences of inadequate security will only become more significant. Companies that treat data protection as a compliance checkbox rather than an operational priority are building exposure that compounds with every record they collect.

Rikka works with businesses to assess security posture, build incident response programs, and align data practices with applicable privacy law. Contact us at info@rikkagroup.com to discuss where your program currently stands.

Further Reading

  1. Pennsylvania Office of Attorney General, “AG Sunday Announces $18 Million National Settlement With 23andMe Over Genetic Data Breach” (July 13, 2026)
  2. DataGuidance, “USA: AGs Reach Settlement With 23andMe Over 2023 Data Breach” (July 2026)
  3. Reuters, “Judge Approves $46.75 Million Payout for 23andMe Data Breach Victims” (July 7, 2026)
  4. Smith Anderson, “Data Privacy in 2026: State Enforcement Takes Center Stage” (January 2026)
This content is for informational purposes only and does not constitute legal advice.