← All stories
● Covered by 2 sources · 3 reportsMedium impact

23andMe Settles $18 Million Data Breach Case Across 42 States

🔄 Updated 72d ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 23andMe settles for $18M with 42 states over data breach.
  • Breach impacted 6.9 million users, including genetic data.
  • New data security measures are now required by 23andMe.
  • Spain fined 23andMe nearly $3M for related breaches.

Overview

Genetic testing company 23andMe has reached an $18 million settlement with a coalition of 42 state attorneys general over a data breach that exposed 6.9 million users' information, including sensitive genetic data. The settlement imposes new cybersecurity requirements on the company.

Details of the Data Breach

The breach, which 23andMe initially failed to recognize, involved credential-stuffing attacks that went unnoticed for several months in 2023. The incident led to the stolen data being found for sale on the dark web. Following confirmation of the breach, 23andMe attributed some blame to consumer password practices.

Regulatory Actions and Fines

Aside from the U.S. settlement, Spain's data protection agency imposed a nearly $3 million fine, underscoring 23andMe's failure to comply with GDPR standards. The firm was criticized for poor cybersecurity practices such as the absence of multifactor authentication and improper breach notification procedures.

Repercussions and Takeaways

As part of the settlement, 23andMe must conduct risk assessments, appoint a data security oversight board, and allow users to delete their genetic data indefinitely. The situation highlights the need for robust data security in companies handling sensitive information.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Spain's data privacy regulator fined 23andMe nearly $3 million for failing to secure customer data, resulting in a significant data breach in April 2023. The breach impacted 6.9 million users globally, with over 2,600 Spaniards affected, highlighting 23andMe's inadequate security measures against known cyber threats.

23andMe will pay $18 million to settle claims from 43 attorneys general over inadequate data protection, following a breach that affected 6.9 million customers. The company failed to implement basic security measures, exposing sensitive genetic data to attackers, some of which was sold on the dark web.

23andMe has agreed to an $18 million settlement for a data breach that exposed 6.9 million users' information. The settlement includes new data protection measures and the company's obligations to ensure better cybersecurity practices moving forward.