On July 14, 2026, Connecticut Attorney General William Tong led a coalition of 42 state attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations tied to the company's 2023 data breach. The breach, which 23andMe disclosed in October 2023, exposed genetic and account data belonging to 6.9 million customers worldwide, including genetic ancestry information for some users that was later published for sale on the dark web.
The headline number attached to this settlement is misleading if you only read one figure in isolation. The deal includes $150 million in allowed claims for participating states, but the states will actually recover only $18 million, paid immediately out of what remains in 23andMe's bankruptcy estate. A separate $46.75 million consumer class-action settlement, already resolved earlier in the same bankruptcy case, covers individual claims from affected U.S. customers who filed by February 17, 2026. Three different dollar figures, three different purposes, and it is easy to conflate them if you only catch the news in passing.

Source: Office of the Connecticut Attorney General, captured August 4, 2026.
What the settlement actually pays out
Three separate figures are attached to this case, and each one covers a different pot of money for a different purpose.
| Figure | What it covers | Who receives it |
|---|---|---|
| $150 million | Allowed claims recognized in the bankruptcy for the 42-state coalition | Not actually paid in full, capped by estate funds |
| $18 million | Actual recovery, paid immediately from available bankruptcy funds | Split among the 42 participating states |
| $46.75 million | A separate consumer class-action settlement in the same bankruptcy | U.S. consumers who filed claims by February 17, 2026 |
The gap between the $150 million allowed and the $18 million actually recovered comes down to bankruptcy math: 23andMe filed for Chapter 11 protection in March 2025, and the states' claims are one of several competing demands on a limited estate. Connecticut's own share of the $18 million works out to $887,729, tied to the 65,766 Connecticut residents whose data was affected. That per-state math scales down fast once you spread $18 million across 42 states with widely varying resident counts.
What investigators found wrong
The multistate investigation, led by Connecticut in the immediate aftermath of the breach, did not find a novel or exotic attack. It found a credential-stuffing breach, the kind that happens when attackers reuse passwords leaked in an unrelated, earlier breach, this time apparently tied to 23andMe's prior data-sharing partnership with MyHeritage, which had itself been breached years earlier. According to the Connecticut Attorney General's press release, the investigation identified several specific security gaps: no password screening against known-breached credential lists, no requirement for multifactor authentication, no rate limiting or intrusion prevention on login attempts, insufficient logging and monitoring to catch a breach in progress, and a failure to investigate an unusual spike in login attempts before the exposure was discovered.
None of those are exotic or expensive controls. They are baseline account-security hygiene that has been standard advice for years, and the AG coalition's core finding was not that 23andMe was hacked by a sophisticated new technique, but that it did not have the basic defenses in place to stop a known, common attack pattern. 23andMe's own initial public response made the exposure worse: the company first denied a breach had occurred, then, once it confirmed one, characterized the incident as a consequence of how individual customers set up their accounts or reused their own passwords, according to the same release.
Why a bankrupt company's privacy commitments still bind the buyer
The most structurally interesting part of this settlement has nothing to do with the dollar figures. When 23andMe's assets, including its consumer genetic database, were sold in bankruptcy to TTAM Research Institute, a nonprofit founded by 23andMe's former CEO Anne Wojcicki, the sale terms carried privacy and security conditions that would likely have appeared in a direct settlement with 23andMe had the company not filed for bankruptcy. TTAM, now reregistered as 23andMe Research Institute, agreed to enhanced data security requirements, an ongoing risk-assessment obligation, the creation of an outside Advisory Board, continued consumer deletion rights, and a commitment to comply with comprehensive privacy laws without carve-outs.
That is the practical lesson worth carrying forward even if your business has nothing to do with genetic testing: a privacy commitment made to your customers does not automatically evaporate the moment your company changes hands, whether through an acquisition, a merger, or a bankruptcy sale. Regulators increasingly treat those commitments as encumbrances that travel with the data itself, not just with the entity that first collected it. If your privacy policy is silent on what happens to customer data in a sale or transfer of the business, that silence is exactly the kind of gap this settlement shows regulators are willing to fill in after the fact.
Figure: The three dollar figures attached to the 23andMe settlement, in millions.
Bottom Line
This settlement is a reminder that "unreasonable data security practices," the phrase Connecticut's investigation used, gets defined by whether basic, well-known controls were in place, not by whether the attack itself was sophisticated. If your business collects sensitive data of any kind, genetic, health, financial, or otherwise, the security bar regulators are applying is baseline account hygiene: password screening, multifactor authentication, rate limiting, and logging that would catch a credential-stuffing attempt before it becomes a breach.
Your privacy policy is the other half of that equation, and it is the part fully within your control regardless of how any individual security incident plays out. It should say plainly what happens to a user's data if your business is acquired, merges, or winds down, and it should accurately describe the categories of sensitive data you collect and how you protect them. Our Privacy Policy Generator builds both of those disclosures into your policy from the start, so the commitments you make to your users are the ones that would actually hold up if your company's ownership ever changed.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.