Genetic testing company 23andMe has reached an $18 million settlement with a coalition of 42 state attorneys general over a data breach that exposed 6.9 million users' information, including sensitive genetic data. The settlement imposes new cybersecurity requirements on the company.
The breach, which 23andMe initially failed to recognize, involved credential-stuffing attacks that went unnoticed for several months in 2023. The incident led to the stolen data being found for sale on the dark web. Following confirmation of the breach, 23andMe attributed some blame to consumer password practices.
Aside from the U.S. settlement, Spain's data protection agency imposed a nearly $3 million fine, underscoring 23andMe's failure to comply with GDPR standards. The firm was criticized for poor cybersecurity practices such as the absence of multifactor authentication and improper breach notification procedures.
As part of the settlement, 23andMe must conduct risk assessments, appoint a data security oversight board, and allow users to delete their genetic data indefinitely. The situation highlights the need for robust data security in companies handling sensitive information.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Spain's data privacy regulator fined 23andMe nearly $3 million for failing to secure customer data, resulting in a significant data breach in April 2023. The breach impacted 6.9 million users globally, with over 2,600 Spaniards affected, highlighting 23andMe's inadequate security measures against known cyber threats.
23andMe will pay $18 million to settle claims from 43 attorneys general over inadequate data protection, following a breach that affected 6.9 million customers. The company failed to implement basic security measures, exposing sensitive genetic data to attackers, some of which was sold on the dark web.
23andMe has agreed to an $18 million settlement for a data breach that exposed 6.9 million users' information. The settlement includes new data protection measures and the company's obligations to ensure better cybersecurity practices moving forward.