By Michele Evans / NYweeklyRecord.com / Date: 7/20/2026
NEW YORK, NY – A company built around the promise of personal genetic discovery is paying for a failure to protect some of the most sensitive information a person can surrender: DNA-linked data.
New York Attorney General Letitia James joined 41 other attorneys general in securing an $18 million settlement from the company formerly known as 23andMe over a 2023 data breach that affected 6.9 million customers, including 305,245 New Yorkers.
The states alleged that the company failed to use reasonable data-security safeguards, failed to adequately monitor for suspicious activity, and did not respond quickly enough as attackers accessed customer accounts through credential-stuffing attacks.
The breach exposed personal profile information and genetic ancestry data. Some information was later offered for sale online, according to the attorney general’s office.
This was not a lost password with ordinary consequences. Genetic information can reveal family connections, ancestry and health-related traits. A compromised credit card can be replaced. A person’s DNA cannot.
Under the settlement, the company must strengthen account security, maintain a comprehensive information-security program, improve monitoring, undergo regular security assessments, and give consumers clearer control over their data. The agreement also restricts misleading statements about privacy and security.
The $18 million recovery is tied to the company’s bankruptcy and is separate from a $46.75 million consumer class-action settlement approved earlier this year. The claims period for that class action has closed, and payments remain delayed while bankruptcy reconciliation continues.
That distinction matters. New Yorkers should not assume this new state settlement automatically creates a new claims process or guarantees an individual payment. The attorney general’s announcement did not identify a direct application process for affected New Yorkers.
The company, now operating under new ownership, has committed to stronger protections and consumer deletion rights. Those promises will matter only if they are enforced and independently tested.
The case also exposes a larger regulatory gap. Millions of people mailed saliva samples to a private company and trusted it to store the resulting data for years. When the business faltered, the data remained an asset with enormous commercial and research value.
Consumers were asked to understand complex privacy policies while the company controlled the infrastructure, the security systems and the terms. That is not equal bargaining power.
New York’s settlement imposes reforms, but accountability cannot end with a dollar figure divided across 42 states. Regulators should disclose how compliance will be monitored, how consumers will be notified of future changes, and what happens if the company changes owners again.
Companies that collect genetic information should be held to a higher standard because the harm can be permanent, deeply personal and shared across families.
The lesson is blunt: if a company profits from DNA, privacy cannot be treated as a feature. It is the product’s most basic obligation.
Sources
New York Attorney General: 23andMe Data-Breach Settlement
23andMe Consumer Class-Action Settlement
23andMe: Data Security Action Plan
Michele Evans is an independent journalist, author, and former ESPN technical producer whose work has appeared in The New York Times.


Leave a Reply