23andMe Genetic Data Breach Settlement Approved Michigan Resolves 2023 Security Incident

Court approves $46.75 million settlement for 23andMe's 2023 genetic data breach; Michigan residents affected and state receives $436,605.

Michigan has resolved its legal claims against 23andMe over a 2023 genetic data breach that exposed personal information for 162,865 state residents. In July 2026, a federal bankruptcy judge approved a $46.75 million class-action settlement affecting approximately 6.4 million U.S. customers, while 43 state attorneys general simultaneously reached an $18 million multistate agreement. Together, these settlements represent the company’s acknowledgment of profound security failures that allowed attackers to access customer names, addresses, genetic ancestry data, and family tree information through a basic credential-stuffing attack over six months.

The breach itself occurred between April and September 2023, discovered and publicly disclosed by 23andMe in October 2023. What makes this case particularly striking is the simplicity of the attack method—hackers used previously leaked passwords from other data breaches to gain unauthorized access to 23andMe accounts. The company later admitted it had failed to implement fundamental cybersecurity protections like rate limiting and intrusion detection systems that would have stopped such attacks almost immediately. Michigan residents represented a significant portion of those affected, which is why Michigan Attorney General Dana Nessel joined other state attorneys general in pressing 23andMe for restitution. The state will receive $436,605 from the multistate settlement fund, though that amount reflects the limited resources available to 23andMe, which filed for Chapter 11 bankruptcy in March 2025.

Table of Contents

What Actually Happened During the 23andMe Genetic Data Breach?

The attack was straightforward but devastating in scope. Hackers obtained lists of usernames and passwords from previous data breaches at other companies—a technique called credential stuffing—and attempted to log into 23andMe accounts. Between April and September 2023, they succeeded with thousands of accounts before 23andMe detected and stopped the unauthorized access. The company later disclosed that the breach affected 6.9 million customers globally, with approximately 162,865 Michigan residents included in that number.

What elevates this breach beyond a typical password compromise is the type of data exposed. Attackers accessed customer names, physical addresses, email addresses, genetic ancestry profiles, and family tree information—some of the most sensitive personal data a company can hold. In a particularly alarming development, subsets of this data were later published for sale on dark web marketplaces, where criminal actors could have acquired information on millions of people. This wasn’t just a database leak; it was a theft of irreplaceable genetic and genealogical information that could be weaponized for identity theft, insurance discrimination, or other malicious purposes for years to come.

How Much Money Did the Settlement Award and Who Gets Paid?

The july 2026 settlement approval unlocked two distinct payout structures, which often confuses affected individuals. The class-action settlement totals $46.75 million, with $14.29 million already distributed to victims before the court approval, and an additional $32.46 million now cleared for distribution. The multistate settlement, negotiated separately by attorneys general, amounts to $18 million but is shared across 43 states—meaning Michigan receives only $436,605 despite having nearly 165,000 affected residents. The limitation exists because 23andMe’s bankruptcy filing in 2025 restricted how much the company can pay across all settlements.

Individual victims can receive up to $10,000 for extraordinary claims (demonstrating measurable harm from the breach), up to $165 for health information that was exposed, and approximately $100 in statutory compensation if they simply prove they were affected. Beyond cash payouts, 23andMe is required to provide five years of free genetic and privacy monitoring services to enrolled customers. The eligible window for claims covers customers who were affected during the May 1 to October 1, 2023 period, were U.S. residents at the time, and received a breach notification notice from the company. One limitation: the statutory compensation of around $100 may seem modest compared to the seriousness of exposing someone’s genetic data, and this represents one of the gaps critics point to when arguing that settlements often undervalue genetic information.

What Types of Personal Information Did Hackers Actually Steal?

The data exposed went far beyond usernames and passwords. Attackers gained access to full names, complete physical addresses, and email addresses for every compromised account. More troubling, they accessed genetic ancestry reports—the core reason people use 23andMe—which contain detailed ethnic and geographic origin information derived from DNA testing. Family tree data was also compromised, meaning relatives’ information could be exposed even if they never directly used 23andMe themselves, since the service allows users to connect and share genealogical information with family members.

This combination of data creates serious risks. Someone’s genetic and genealogical information, when paired with their name and address, can be used for identity theft, especially since many people use genetic information for family and ancestry-related online accounts. Insurance companies, employers, or law enforcement agencies could theoretically misuse genetic data. The fact that subsets of this information appeared on dark web marketplaces indicates that criminal actors have already obtained the stolen credentials and are actively trying to profit from them. For Michigan residents specifically, the exposure was equally comprehensive—the breach made no distinctions by geography.

How Can Michigan Residents Actually File a Claim?

To submit a claim under either settlement, affected Michigan residents must first verify they meet the eligibility requirements: they must have been 23andMe customers between May 1 and October 1, 2023, must be U.S. residents, and must have received a breach notification from 23andMe. The settlement website at 23andmedatasettlement.com provides detailed instructions and allows claimants to submit documentation electronically. For extraordinary claims seeking the higher $10,000 payout, individuals must provide evidence of actual harm—medical identity theft, unauthorized insurance claims, or similar documented damages.

The tradeoff with class-action settlements like this one is that the payout amount depends partly on how many people submit claims. If 100,000 Michigan residents file claims, each person receives a smaller slice of the settlement pie than if only 10,000 residents participate. This creates an incentive problem: people who suffered serious identity theft may receive significant compensation, while those who simply want financial recompense for privacy violation may receive much less. Additionally, the five-year monitoring service sounds valuable but has practical limitations—it can only alert you to future identity theft; it cannot undo exposure that already occurred or prevent someone who purchased stolen data from using it years later.

What Security Failures Allowed the Breach to Happen in the First Place?

The settlements revealed a troubling fact about 23andMe’s security posture: the company had not implemented basic defensive technologies that would have stopped this attack nearly instantly. The multistate settlement found that 23andMe failed to employ safeguards specifically against credential-stuffing attacks—essentially, it did not implement rate limiting to stop repeated login attempts from the same source IP address, nor did it deploy intrusion prevention systems that could have flagged suspicious login patterns. The company also lacked adequate logging and monitoring tools, meaning even if attackers did get in, 23andMe might not have detected them quickly. This is particularly alarming because credential-stuffing is one of the oldest, most common attack tactics in cybersecurity.

It’s not a sophisticated zero-day exploit or a breakthrough hacking technique; it’s a brute-force attack that relies on password reuse. Any security team should have considered this threat, especially for a company storing genetic data. One warning: the security failures identified in the settlement suggest that 23andMe’s security infrastructure lagged significantly behind industry standards for a company handling such sensitive data. For users evaluating whether to use genetic testing services now, this should raise questions about what security measures other genetics companies have in place.

What Are the Ongoing Security Requirements Imposed on 23andMe?

As part of the settlement, 23andMe is now bound by enhanced data security requirements going forward. The company must undergo appropriate risk analyses before implementing new systems or services, maintain an advisory board focused on security and privacy, and remain compliant with applicable state comprehensive privacy laws. Additionally, 23andMe must continue offering customers the right to delete their genetic data—a requirement that addresses one of the concerns about genetic privacy: the inability to remove your DNA information from corporate databases.

However, these forward-looking requirements apply only to 23andMe’s future conduct. They do not retroactively secure the genetic and genealogical data already stolen from millions of people. The damage is already done for the 162,865 Michigan residents and millions of others globally. The monitoring services and compensation aim to mitigate harm, but they cannot undo the fact that someone’s complete genetic profile and family tree now exists in criminal databases and dark web marketplaces.

How Does the Bankruptcy Filing Affect the Settlement Amounts?

23andMe filed for Chapter 11 bankruptcy protection in March 2025, more than a year after the breach was disclosed. This filing is directly relevant to why Michigan receives only $436,605 from the multistate settlement despite having 162,865 affected residents—the company’s bankruptcy assets are limited, and multiple creditors (including settlement claimants) must share whatever funds are available. The bankruptcy filing also explains why the $46.75 million class-action settlement had to be staged, with $14.29 million distributed before final approval and another $32.46 million allocated afterward based on what the company could actually pay.

The timing of the bankruptcy is significant. By filing in 2025, 23andMe potentially limited future liability exposure and gained court-supervised protection from lawsuits, even as settlement negotiations continued. For Michigan residents, this means the state’s enforcement leverage was constrained by the company’s financial condition. The $436,605 that Michigan receives will likely fund victim assistance programs, consumer education, or other remedial measures rather than being distributed directly to affected residents, though the details depend on how Michigan’s Attorney General allocates those funds.


You Might Also Like