23andMe reaches $18 million settlement with states for massive breach
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.
A coalition of 42 state attorneys general on Tuesday said they reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach exposing 6.9 million people’s information, including genetic ancestry data.
The agreement also requires new data protection measures from the 23andMe Research Institute, a nonprofit founded in May 2025 by 23andMe CEO Anne Wojcicki. The institute absorbed 23andMe’s assets, including genetic data.
The new requirements include undertaking risk assessments and appointing a special board to oversee data security. The settlement also requires that 23andMe customers maintain their right to throw out their genetic samples and delete personal data indefinitely.
Source: https://therecord.media/genetic-testing-settlement-data-breach
Related breach coverage
- Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack2026-07-21
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.
- Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments2026-08-01
The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.
- Valarian Raises $50 Million for Sovereign Infrastructure Control Layer2026-07-14
UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek.
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking2026-08-03
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek.