The Breach
In October 2023, 23andMe disclosed a data breach affecting about 6.9 million users. The attackers did not break the company’s systems directly; instead they used “credential stuffing” — logging in with usernames and passwords leaked from other sites where people had reused the same credentials. Once inside those accounts, they harvested personal and ancestry information and, through the “DNA Relatives” feature, pulled data on millions of connected relatives who had never been directly hacked. Some of the stolen data was offered for sale online, in one case targeting people by ethnicity.
The breach was especially sensitive because genetic and ancestry data is permanent and deeply personal — you cannot change it the way you change a password.
The Settlement and Bankruptcy
23andMe agreed to a $30 million settlement to resolve class-action claims, along with three years of security monitoring and stronger safeguards such as mandatory two-factor authentication. But the company’s finances were failing, and it later filed for bankruptcy — a development that can reduce or delay what class members actually receive, since settlement obligations compete with other creditors. The bankruptcy also raised its own alarms about what happens to millions of people’s genetic data when the custodian is sold off.
This is the key caveat: a settlement figure on paper does not guarantee full payment when the defendant is insolvent.
What Users Should Know
If you used 23andMe, change any reused passwords, turn on two-factor authentication, and review what data you shared and whether you want to delete your account and destroy your sample. More broadly, the breach is a lesson in password reuse: a single leaked password from any site can unlock accounts everywhere you used it, so use unique passwords and a password manager.
Before You Act
Thinking About Filing a Claim?
Most plaintiff lawyers offer a free initial consultation and work on contingency, meaning no fee unless there is a recovery. LawsuitWatch is not a law firm: we publish explainers, and we do not provide legal advice, representation or referrals. Your state bar directory is the reliable place to find and verify a lawyer.
23andMe Data Breach Lawsuit: The $30 Million Settlement: Frequently Asked Questions
Answers to the most common questions about this case and your legal options.
How did the 23andMe breach happen?
Through credential stuffing — attackers logged into accounts using passwords leaked from other sites where users had reused them, then harvested ancestry data, including on millions of connected relatives via the DNA Relatives feature. About 6.9 million users were affected.
How much is the 23andMe settlement?
$30 million plus three years of security monitoring and stronger safeguards. But 23andMe later filed for bankruptcy, which can reduce or delay what class members actually receive.
What should 23andMe users do?
Change any reused passwords, enable two-factor authentication, and review your shared data, including whether to delete your account and destroy your sample.
Legal Disclaimer
This article is general legal information, not legal advice, and does not create an attorney-client relationship. Case status, eligibility criteria, and any amounts described are as reported at the date shown and may change. Consult a licensed attorney in your jurisdiction about your own situation.