Utah and 42 other states announced Tuesday an $18 million multistate settlement with genetic testing company 23andMe to resolve allegations regarding a 2023 data breach that exposed the sensitive genetic information of approximately 6.9 million consumers worldwide.
Multistate Settlement Details
The settlement, announced by the Utah Attorney General's office on July 23, 2026, follows a period of legal action involving various state officials. According to an announcement from the Utah Attorney General, the agreement addresses claims stemming from the breach that occurred in October 20rypt3.
In a statement released July 14, Pennsylvania Attorney General Dave Sunday noted that he joined a coalition of 4 and 42 states to reach the $18 million bankruptcy claim settlement. The investigation into 23andMe's practices was initiated by Attorneys General in the immediate aftermath of the cyberattack.
Allegations of Negligence
The breach, which 23andMe first announced in October 2023, compromised a wide range of user data, including genetic ancestry information. Investigators found that subsets of this sensitive data were later published for sale on the dark web.
Attorney General Sunday criticized the company's response to the incident, stating, "This company was trusted by millions of Americans to safeguard very private data and information, but failed to do so, learning about a data breach far too late, then pointing fingers at their own customers." He further described the company's actions as "appalling," alleging that 23andMe attempted to deny responsibility and wash its hands of wrongdoing after the breach was confirmed.
Security Vulnerabilities Identified
A multistate investigation found that 23andMe engaged in unreasonable data security practices. Specific failures identified by investigators included a lack of safeguards against "credential stuffing" attacks, which involve using stolen passwords from other websites to gain unauthorized access. The company also failed to use blocklists for known breached passwords or implement multi-factor authentication.
Additional security lapses reported by the Pennsylvania Attorney General's office included a failure to implement appropriate rate limiting or intrusion prevention, as well as a failure to utilize logging and monitoring tools that could have detected the breach. Investigators also noted that the company failed to investigate unusual login patterns, such as massive spikes in login attempts, and failed to remediable known vulnerabilities or properly test design features.
Class Action and Impact
The breach was particularly significant due to 23andMe's partnership with MyHeritage, a company that had been compromised years prior, exposing thousands of credentials shared between the two websites. This connection facilitated the credential stuffing attack used by cybercriminals.
In addition to the $18 million state settlement, 23andMe agreed to a separate $46.75 million class-action settlement within its bankruptcy proceedings. This class-action fund was intended to provide relief to affected U.S. consumers who submitted claims by February 17, 2026. Impacted individuals were expected to receive email notifications regarding their eligibility for these funds.
Bankruptcy and Asset Sale
The legal resolution comes as part of the fallout from 23andMe's March 2025 bankruptcy filing. During the bankruptcy process, the company's assets—most notably its vast repository of consumer genetic data—were sold to the TTAM Research Institute. This non-profit organization was formed by 23andMe founder and former CEO Anne Wojcicki.
The sale included several security mandates that officials noted would likely have been required in a standard settlement agreement had the company not filed for bankruptcy. These terms include enhanced data security requirements, mandatory risk analysis, the establishment of an Advisory Board, and a commitment to follow comprehensive privacy laws. The organization has since re-registered as the 23andMe Research Institute and is expected to act as a safer custodian of genetic information.
Participating States
The $18 million settlement includes contributions from a wide coalition of states. Joining Utah in the agreement are the Attorneys General from Alaska, Alabama, Arkansas, Arizona, Colorado, Connecticut, Delaware, the District of Columbia, Florida, Georgia, Idaho, Iowa, Illinois, Indiana, Kansas, Kentucky, Louisiana, Massachusetts, Maryland, Maine, Michigan, Minnesota, North Carolina, North Dakota, New Hampshire, New Jersey, New Mexico, New York, Ohio, Oklahoma, Oregon, South Carolina, South Dakota, Tennessee, Texas, Virginia, Vermont, Washington, Wisconsin, and West Virginia.
In Pennsylvania, the settlement is expected to provide $491,902 in relief, as the state reported that nearly 200,000 residents were impacted by the breach.