New York Attorney General Letitia James said a bipartisan multistate coalition secured payments and new data-security requirements after a breach affecting millions of 23andMe customers.
What happened
New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general have secured an $18 million settlement from 23andMe over alleged failures to protect customers' private genetic data, the attorney general's office said Tuesday.
The deal requires new data-protection measures for 23andMe customer data and more than $705,000 in payments to New York, according to the office. James' announcement frames the resolution as part of a broader state response to the genetic testing company's October 2023 breach.
According to the attorney general's office, 23andMe announced in October 2023 that it had discovered a breach affecting 6.9 million consumers, including 305,245 in New York. The office said the exposed data included genetic ancestry information and that some customer data was published for sale on the dark web.
The multistate investigation found alleged security failures including insufficient safeguards against credential-based cyberattacks, lack of appropriate rate limiting or intrusion prevention, inadequate logging and monitoring, failure to address unusual login patterns, failure to fix known vulnerabilities and insufficient review and testing of design features.
The settlement also follows 23andMe's bankruptcy. The attorney general's office said 23andMe filed for bankruptcy protection in March 2025, that James and the coalition filed claims tied to the data breach investigation, and that James joined 27 other attorneys general in suing 23andMe in June 2025 to protect personal genetic information during the bankruptcy.
As part of the bankruptcy process, 23andMe customer data was sold to TTAM Research, a nonprofit formed by 23andMe's founder and former CEO, according to the release. The office said TTAM, now reregistered as 23andMe Research Institute, must adopt new information and data-security requirements, including risk analysis, a data-security advisory board and continued consumer rights to delete their information.