NEW YORK — A bipartisan coalition of 43 other attorneys general, including New York State Attorney General Letitia James, has secured $18 million from 23andMe for failing to protect customers’ private genetic data.
In October 2023, the genetic testing company announced it had discovered a data breach affecting 6.9 million consumers, including 305,245 in New York.
The breach exposed a broad range of customer data, including genetic ancestry information. Some customers’ data was even published for sale on the dark web.
As part of the settlement, the coalition has secured new data protection requirements to secure 23andMe customer data. 23andMe will also pay more than $705,000 to New York.
“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” James said in a press release.
“New Yorkers trusted 23andMe with their sensitive and personal genetic data only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law, and strict rules will be put in place to protect their customers.”
23andMe learned about the breach months after impacted personal information was publicly available. The company first denied a breach and then, once it was confirmed, blamed costumers for how their accounts were set up or how passwords were used.
In the immediate aftermath of the data breach, the coalition began a multistate investigation and found 23andMe failed to take critical security measures, including:
— Safeguards against cyber-attacks utilizing stolen credentials, including comparing passwords against blocklists of known breached passwords or requiring multifactor authentication.
— Appropriate rate limiting or intrusion prevention.
— Logging, monitoring or other tools likely to detect a data breach.
— Investigating or addressing unusual login patterns. For example, a massive spike in login attempts.
— Fixing known vulnerabilities.
— Properly reviewing and testing design features.
In March 2025, 23andMe filed for bankruptcy protection, and the coalition filed claims related to the data breach investigation. In June 2025, a coalition of James and 27 other attorneys general sued 23andMe to protect Americans’ personal genetic information during the company’s bankruptcy.
NY AG joins coalition to stop 23andMe from selling user data
As a result of the bankruptcy, 23andMe’s customer data was sold to TTAM Research, a nonprofit formed by 23andMe’s founder and former CEO.
The coalition have secured new information and data security requirements at TTAM to protect customers’ data and prevent future breaches. These measures include appropriate risk analysis, the addition of an advisory board on data security and continuing to offer consumers the right to delete their information.
These terms aim to ensure TTAM, now reregistered as 23andMe Research Institute, will be a safer custodian of genetic data moving forward.
Joining James in securing this settlement are the attorneys general of Alabama, Alaska, Arizona, Arkansas, Colorado, Connecticut, Delaware, Florida, Georgia, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, North Carolina, North Dakota, New Hampshire, New Jersey, New Mexico, Ohio, Oklahoma, Oregon, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Vermont, Washington, Wisconsin, West Virginia and the District of Columbia.