23andMe, now Chrome Holding Co., agreed to settle with 42 state attorneys general over allegations that the company failed to implement cybersecurity measures that resulted in a data breach in October 2023 affecting 6.9 million customers.
Settlement Terms
The settlement requires payment of $18 million to the participating states and includes commitments to implement additional data security measures intended to improve protection of consumer information and reduce the risk of future data breaches.
The multistate action was filed while 23andMe was in bankruptcy proceedings. The new security obligations apply to TTAM Research, the company formed by 23andMe founder and former Chief Executive Officer Anne Wojcicki, which acquired the company’s data and is now registered as 23andMe Research Institute.
The settlement states that New York will receive over $705,000 from the proceeds distributed to participating states.
Results of the Multistate Investigation
The October 2023 data breach investigation determined that the cause of the data breach was a credential stuffing campaign. Credential stuffing involves using credentials obtained from breaches at other companies to attempt access to accounts on a different platform. The attacks succeed when individuals use the same credentials in several accounts.
The investigation found that 23andMe lacked multiple cybersecurity measures intended to prevent credential-based attacks. The following deficiencies had been identified:
- The company did not check user passwords in the list of blocklisted breached passwords.
- The company did not require multifactor authentication.
- The company did not implement rate limiting.
- The company did not implement intrusion prevention measures.
- The company maintained insufficient logging and monitoring capabilities.
- The credential stuffing campaign was not detected for five months from April 2023 to September 2023.
- The company did not investigate or address unusual login patterns, including a substantial increase in login attempts that indicated a credential stuffing campaign.
- The company failed to address known vulnerabilities and to review and test platform design features.
After discovery of the credential stuffing campaign, 23andMe maintained that the compromised accounts resulted from customers reusing credentials rather than from a breach.
Bankruptcy and Ownership Changes
23andMe filed for bankruptcy protection in March 2025, then sold the company’s data to TTAM Research, a company formed by Anne Wojcicki. TTAM Research is now registered as 23andMe Research Institute and is subject to the settlement’s data security requirements.
Previous Financial Penalties
23andMe previously agreed to pay $46.75 million in compensation to individuals affected by the data breach. Data protection authorities in Spain imposed a $2.75 million fine and authorities in the United Kingdom imposed a $3.1 million fine related to the 23andMe data breach.
California did not participate in the multistate settlement because it filed a separate lawsuit. A bankruptcy judge ruled that California cannot seek monetary relief because of the company’s Chapter 11 reorganization plan.
Statements From State Officials
New York Attorney General Letitia James said the settlement addresses allegations that 23andMe failed to protect customers’ personal information with appropriate cybersecurity measures. The settlement requires payment for alleged legal violations and establishes data security requirements intended to protect customer information (which may include PHI) in the future.