# 23andMe

Type: Company (ME)

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/23andme
Canonical HTML page: https://getcyberbrief.com/entity/23andme

## Timeline

- **2026-07-15**: Settlement Distribution Announced — 42-state $18 million settlement is finalized; Iowa announced to receive over $439,000 from the bankruptcy estate, with immediate distribution.
- **2026-07-14**: Settlement Announced — More than 40 state AGs announce an $18 million settlement resolving investigations into the breach.
- **2026-07-08**: Settlement Approved — Bankruptcy Judge Brian Walsh approves $46.75 million settlement, deeming it fair; remaining $32.46M to be paid.
- **2026-07-07**: Court Orders $46.75 Million Payout — A California bankruptcy judge rules that Chrome Holding must pay $46.75 million to breach victims, to be distributed by Kroll Restructuring within five business days.
- **2026-02**: Claims Filing Deadline — Deadline for consumers affected by the breach to submit claims for compensation through a dedicated website.
- **2025-03**: 23andMe Files for Bankruptcy — Citing mounting legal liabilities and declining consumer trust, 23andMe files for Chapter 11 protection in U.S. bankruptcy court.
- **2025-03**: Bankruptcy Filing — 23andMe declares Chapter 11 bankruptcy amid plummeting sales and breach-related liabilities.
- **2025-03**: Chapter 11 Bankruptcy Filed — 23andMe files for bankruptcy protection, citing litigation costs, demand decline, and competition.
- **2025**: Bankruptcy Auction Won by Chrome Holding — Anne Wojcicki's Chrome Holding (operating as TTAM Research Institute) wins 23andMe's core assets with a $305 million bid.
- **2025**: Asset Acquisition by Nonprofit — A nonprofit entity led by co-founder Anne Wojcicki acquires 23andMe's assets out of bankruptcy.
- **2023-12**: Breach Confirmed — Company SEC filing reveals direct access to 14,000 accounts and exposure of 6.9 million users through connected profiles.
- **2023-10**: 23andMe Data Breach — Hackers use credential stuffing to access 14,000 accounts, leveraging the DNA Relatives feature to ultimately expose the genetic profiles of 6.9 million users.
- **2023-10**: Breach Investigation Launched — 23andMe begins investigating after a threat actor claims to have obtained millions of user records.
- **2023-10**: Credential Stuffing Breach — Hackers use reused credentials to access accounts and DNA Relatives feature, exposing data of 6.9 million customers.
- **2023-10**: 23andMe Cyberattack — A credential-stuffing attack compromises 6.9 million user accounts, exposing names, photos, birth years, locations, and genetic ancestry data. Targeted groups included Ashkenazi Jewish and Chinese users.

## Recent coverage (4 stories)

### Iowa Gets $439K in $18M 23andMe Breach Settlement: A Cyber Wake-Up Call
2026-08-03 05:14:24 · Sentiment: Neutral · Impact: 5/10 · Sources: 2

The 2023 23andMe credential-stuffing attack that leaked data on 6.9M users concludes with an $18M multi-state settlement, including $439K for Iowa. For cybersecurity professionals, it underscores the existential threat that poor authentication poses to genetic data and the bankruptcy-level consequences that follow.
Full story: https://getcyberbrief.com/story/iowa-23andme-breach-settlement-cyber

### How a credential-stuffing attack exposed 6.9M genetic profiles at 23andMe
2026-07-25 08:04:30 · Sentiment: Negative · Impact: 7/10 · Sources: 3

A 2023 credential-stuffing attack on 23andMe compromised 6.9 million customer accounts, leaking sensitive genetic and personal data. The breach, now resolved with a $46.75M settlement after bankruptcy, underscores the catastrophic risk of password reuse and the insurability of biometric data platforms.
Full story: https://getcyberbrief.com/story/23andme-credential-stuffing-breach-6-9m

### 14K Account Takeover to 6.9M Records: Anatomy of 23andMe's $18M Breach
2026-07-19 23:47:44 · Sentiment: Negative · Impact: 7/10 · Sources: 7

The $18 million settlement reveals how a credential-stuffing attack on 14,000 23andMe accounts spiraled into a 6.9-million-record exposure. Cybersecurity pros must dissect this as a textbook case of social-network feature abuse and delayed breach notification.
Full story: https://getcyberbrief.com/story/23andme-breach-14k-to-6-9m-accounts-18m-settlement

### Credential Stuffing to 6.9M Exposures: 23andMe Breach Ends in $47M Penalty
2026-07-08 01:15:15 · Sentiment: Negative · Impact: 7/10 · Sources: 1

The 2023 23andMe attack, which started with simply reusing leaked credentials, ultimately exposed the genetic and health data of 6.9 million users—and now costs $46.75 million. For cybersecurity teams, it is a textbook case of why basic anti‑credential‑stuffing controls and multi‑factor authentication are non‑negotiable for any platform holding sensitive data.
Full story: https://getcyberbrief.com/story/23andme-credential-stuffing-breach-6-9m-payout

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.