🔒 Data Privacy & Tech Updated August 2026

23andMe Data Breach Lawsuit: The $30 Million Settlement

Hackers accessed the ancestry and genetic data of 6.9 million 23andMe users through a credential-stuffing attack. The company agreed to a $30 million settlement — then filed for bankruptcy, complicating payouts.

Category

Data Privacy & Tech

Coverage

Settled ($30M)

Last Updated

August 2026

Content Type

Legal Analysis

The Breach

In October 2023, 23andMe disclosed a data breach affecting about 6.9 million users. The attackers did not break the company’s systems directly; instead they used “credential stuffing” — logging in with usernames and passwords leaked from other sites where people had reused the same credentials. Once inside those accounts, they harvested personal and ancestry information and, through the “DNA Relatives” feature, pulled data on millions of connected relatives who had never been directly hacked. Some of the stolen data was offered for sale online, in one case targeting people by ethnicity.

The breach was especially sensitive because genetic and ancestry data is permanent and deeply personal — you cannot change it the way you change a password.

The Settlement and Bankruptcy

23andMe agreed to a $30 million settlement to resolve class-action claims, along with three years of security monitoring and stronger safeguards such as mandatory two-factor authentication. But the company’s finances were failing, and it later filed for bankruptcy — a development that can reduce or delay what class members actually receive, since settlement obligations compete with other creditors. The bankruptcy also raised its own alarms about what happens to millions of people’s genetic data when the custodian is sold off.

This is the key caveat: a settlement figure on paper does not guarantee full payment when the defendant is insolvent.

What Users Should Know

If you used 23andMe, change any reused passwords, turn on two-factor authentication, and review what data you shared and whether you want to delete your account and destroy your sample. More broadly, the breach is a lesson in password reuse: a single leaked password from any site can unlock accounts everywhere you used it, so use unique passwords and a password manager.

Before You Act

Thinking About Filing a Claim?

Most plaintiff lawyers offer a free initial consultation and work on contingency, meaning no fee unless there is a recovery. LawsuitWatch is not a law firm: we publish explainers, and we do not provide legal advice, representation or referrals. Your state bar directory is the reliable place to find and verify a lawyer.

23andMe Genetic Data Data Breach

23andMe Data Breach Lawsuit: The $30 Million Settlement: Frequently Asked Questions

Answers to the most common questions about this case and your legal options.

How did the 23andMe breach happen?

Through credential stuffing — attackers logged into accounts using passwords leaked from other sites where users had reused them, then harvested ancestry data, including on millions of connected relatives via the DNA Relatives feature. About 6.9 million users were affected.

How much is the 23andMe settlement?

$30 million plus three years of security monitoring and stronger safeguards. But 23andMe later filed for bankruptcy, which can reduce or delay what class members actually receive.

What should 23andMe users do?

Change any reused passwords, enable two-factor authentication, and review your shared data, including whether to delete your account and destroy your sample.

LawsuitWatch Legal Research Team

Data Privacy & Tech Litigation Desk

LawsuitWatch publishes plain-language explainers on active consumer litigation: what a case alleges, who it may affect, and what the process involves. We are not a law firm and do not provide legal advice or representation. Where a figure or filing matters to a decision you are making, verify it against the court record or the official settlement administrator before relying on it. Last updated: August 2026.