23andMe reaches $18 million settlement with states for massive breach
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.
A coalition of 42 state attorneys general on Tuesday said they reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach exposing 6.9 million people’s information, including genetic ancestry data.
The agreement also requires new data protection measures from the 23andMe Research Institute, a nonprofit founded in May 2025 by 23andMe CEO Anne Wojcicki. The institute absorbed 23andMe’s assets, including genetic data.
The new requirements include undertaking risk assessments and appointing a special board to oversee data security. The settlement also requires that 23andMe customers maintain their right to throw out their genetic samples and delete personal data indefinitely.
Source: https://therecord.media/genetic-testing-settlement-data-breach
Related breach coverage
- Valarian Raises $50 Million for Sovereign Infrastructure Control Layer2026-07-14
UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek.
- New Index Tracks Material Breaches — And Refuses to Add Up the Losses2026-07-20
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
- U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog2026-07-18
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. This week, Microsoft’s July 2026 Patch Tuesday addressed the SharePoint remote code execution bug […]
- Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive2026-07-17
(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.
