23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit
23andMe, now operating as Chrome Holding Co., has agreed to an $18 million settlement with a coalition of 42 state attorneys general stemming from a data breach that exposed customer information. The multistate action represents one of the more significant coordinated enforcement responses to a consumer genetic data incident.
Why this matters: Genetic data is not like a leaked password you can reset. It reveals ancestry, health risks, and biological family — information that is permanently yours and permanently sensitive. Millions of people trusted 23andMe with some of the most personal data that exists. The company then suffered a breach, went through bankruptcy, and changed hands. Eighteen million dollars spread across 42 states is not a serious deterrent for a company sitting on that kind of data. The harder question is what happens to all that DNA now that a new company owns it.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.