23andMe Genetic Data Breach Settlement Approved Michigan Resolves 2023 Security Incident

Michigan and 41 other states settled with 23andMe over its 2023 genetic data breach, though bankruptcy limits payouts to just $18 million of the $150 million in allowed claims.

Michigan’s settlement with 23andMe over its 2023 genetic data breach was officially approved in July 2026, marking the first major resolution in a case that exposed the genetic information of millions. The state joined 41 other attorneys general in securing a settlement that will provide partial compensation to affected customers, though 23andMe’s bankruptcy filing in March 2025 significantly reduced what consumers will ultimately receive. The agreement reflects a broader reckoning with how genetic testing companies handle one of the most sensitive forms of personal data. The breach itself occurred in October 2023, when 23andMe announced that bad actors had gained access to customer accounts through credential-stuffing attacks—using passwords leaked from other breaches to gain entry to the platform.

Approximately 6.9 million customers worldwide had their genetic ancestry information and personal data compromised, including 163,000 Michiganders. Shortly after, the stolen data appeared for sale on the dark web, making the exposure permanent and impossible to contain. Michigan’s case against 23andMe represents one of the first major test cases for holding genetic testing companies accountable for security failures. The settlement amount—$436,605 to Michigan—is modest compared to the scale of the breach, a reality tied directly to the company’s financial struggles following the incident.

Table of Contents

How Big Was the 23andMe Data Breach and Who Was Impacted?

The October 2023 23andMe breach affected 6.9 million customers globally, with genetic ancestry data and detailed personal information exposed. In Michigan alone, 163,000 residents discovered their genetic profiles had been compromised, making it one of the largest-scale exposures of DNA data in U.S. history. The attackers used credential-stuffing techniques, a relatively unsophisticated approach where login credentials obtained from previous breaches of other companies were automatically tried against 23andMe accounts—a method that would have been largely prevented by basic security measures like password blocklists or mandatory multifactor authentication.

The data exposed included not just raw genetic ancestry results, but also customer names, email addresses, dates of birth, and in some cases health-related information. Once the breach occurred, the stolen data was quickly monetized, with threat actors offering it for sale on dark web marketplaces. This meant that the exposure couldn’t be reversed or contained—the genetic profiles of millions of people entered a permanent shadow economy where they could be purchased and misused indefinitely. A customer who discovered their 23andMe account had been compromised couldn’t simply reset their password and assume the problem was solved; their genetic data was already in the hands of criminals and potentially identity thieves or insurance companies seeking to discriminate based on genetic predispositions.

What Security Failures Allowed the Breach to Happen?

regulatory investigations revealed that 23andme had failed to implement basic security safeguards that are standard across the industry. The company did not maintain a blocklist of known compromised passwords—a preventative measure that would have immediately rejected login attempts using credentials from known breaches. Additionally, 23andMe did not require multifactor authentication, the two-step verification process that adds a second layer of protection beyond just a password. These weren’t cutting-edge security practices; they were foundational defenses that had been standard practice for years by the time of the breach.

The credential-stuffing attack was particularly effective because 23andMe’s customers were using the same passwords on multiple websites. When those passwords leaked from other companies—retailers, social media platforms, email providers—attackers could immediately turn around and test them against 23andMe accounts. A customer who used the same password for their 23andMe account and their LinkedIn account found themselves vulnerable when LinkedIn’s data was breached. The limitation of focusing on this attack vector is that even customers with unique, strong passwords remained vulnerable if 23andMe’s systems themselves were compromised in other ways, though in this case the company’s own negligence was the primary culprit.

What Was the Settlement Agreement and What Will Customers Actually Receive?

The settlement approved in July 2026 involved 42 state attorneys general working together to recover damages on behalf of Michigan residents and customers from other states. Michigan Attorney General Dana Nessel announced the multistate coalition effort, which pursued claims through the U.S. Bankruptcy Court for the Eastern District of Missouri. The total amount allowed in claims was $150 million, but 23andMe’s bankruptcy filing in March 2025 dramatically reduced what would actually be paid. The company, which filed for Chapter 11 bankruptcy protection, ultimately agreed to pay only $18 million to resolve the states’ claims—bringing the actual recovery down to 12% of the total claim value.

Michigan’s allocation from the $18 million settlement fund was $436,605, distributed through the bankruptcy proceedings. Separate from the multistate settlement with attorneys general, there is also a class-action settlement worth $46.75 million that 23andMe agreed to pay to compensate affected U.S. consumers directly. These two settlements operate independently: the state settlement compensates governments for their enforcement costs, while the consumer class-action settlement provides payments to the individuals whose data was actually breached. Given 23andMe’s financial status, neither settlement comes close to fully compensating victims for the lasting privacy violation.

Should Consumers Still Use Genetic Testing Services After This Breach?

The 23andMe breach raises fundamental questions about the privacy-protection practices at genetic testing companies and whether consumers should be comfortable providing their DNA to these services. The breach itself wasn’t caused by outdated technology or an inevitable vulnerability—it resulted from the company’s deliberate choice not to implement security measures it could have afforded. That decision suggests either a cost-cutting mentality or a fundamental misalignment of priorities between shareholder interests and customer protection.

However, the market for genetic ancestry testing and health insights remains strong, and many consumers decide the benefits outweigh the risks. If you choose to use genetic testing services, there are protective steps: use a unique, strong password that you don’t use anywhere else; enable multifactor authentication if the service offers it; and be cautious about what health information you share with the platform. The tradeoff is that even a conscientious consumer who takes every possible precaution can still be exposed to a breach caused by the company’s security failures, as happened to the 163,000 affected Michiganders and millions of others.

What Does This Settlement Mean for Other Genetic Testing Companies?

The 23andMe settlement signals to other genetic testing companies that regulatory agencies will hold them accountable for security failures, particularly when those failures involve not implementing basic protective measures. Competitors like Ancestry.com, MyHeritage, and others operate in the same space and face the same pressure to keep costs down while delivering results to customers quickly. The lesson of the 23andMe case is that cost-cutting on security—especially preventative measures like password blocklists and multifactor authentication—creates liability that ultimately exceeds the savings.

The settlement also highlights a critical limitation: even when regulators win enforcement cases against companies for massive privacy breaches, the actual compensation to consumers is often far less than the harm inflicted. A genetic data breach is permanent and irreversible. The exposed DNA of 163,000 Michiganders will remain accessible on dark web marketplaces indefinitely, potentially used for fraud, identity theft, insurance discrimination, or other harms that haven’t yet been conceived. The $436,605 Michigan received and the broader $46.75 million consumer settlement don’t approach adequate compensation for the scale of the exposure.

The Role of Bankruptcy in Limiting Consumer Compensation

When 23andMe filed for Chapter 11 bankruptcy in March 2025, it fundamentally changed the landscape for victims seeking compensation. In bankruptcy proceedings, a company’s assets are distributed according to a strict priority order, with secured creditors first and then unsecured creditors—which includes victims of privacy breaches. The company’s financial troubles meant that even when attorneys general and consumers won their cases, the actual money available to pay out was a fraction of what they sought.

This dynamic creates perverse incentives: companies can calculate that even if caught and sued for a major security breach, bankruptcy protection limits the ultimate financial consequence. The 23andMe case is a textbook example, with the company’s bankruptcy reducing the $150 million in allowed claims to $18 million—an 88% reduction. The reduction demonstrates how corporate financial engineering can substantially diminish the legal accountability for breaches.

What Happens to the Genetic Data That Was Already Stolen?

One often-overlooked aspect of the settlement is that it does nothing to recover the stolen genetic data or remove it from dark web marketplaces. The data breached from 23andMe in 2023 has already been sold and is likely now in the permanent possession of multiple criminal actors, data brokers, and potentially foreign governments or bad actors seeking to build genetic databases.

No settlement or court order can make that data disappear. The permanent nature of genetic data exposure distinguishes it from other forms of privacy breaches: a stolen credit card number can be deactivated and replaced, but genetic data is immutable. You cannot get a new genome if yours is compromised, which is why genetic testing companies face a unique responsibility to protect their databases with the highest available security standards.

Frequently Asked Questions

How much money is Michigan getting from the settlement?

Michigan’s allocation from the multistate settlement is $436,605 from the $18 million settlement fund. Separately, there is a $46.75 million class-action settlement for individual consumers affected by the breach.

What caused the 23andMe breach?

The breach resulted from credential-stuffing attacks exploiting weak security practices. 23andMe had not implemented password blocklists to prevent using compromised passwords or required multifactor authentication.

How many people were affected?

Approximately 6.9 million customers globally had genetic ancestry and personal data exposed, including 163,000 residents of Michigan.

Why is the settlement amount so small compared to the original claims?

23andMe filed for Chapter 11 bankruptcy in March 2025, which reduced the $150 million in allowed claims to $18 million in actual payouts—an 88% reduction.

Can the stolen genetic data be recovered?

No. The stolen data was sold on dark web marketplaces and cannot be recovered or removed from circulation. The genetic profiles of affected customers remain permanently compromised.


You Might Also Like