Judge orders $47 million payout to victims of 23andMe data breach
23andMe, the U.S. consumer genetics company that builds individual genetic profiles from at-home DNA kits, faced intense scrutiny after a data breach in 2023 exposed personal information of millions of customers. The hack, discovered in late 2023, involved unauthorized access to the company’s cloud-based database, revealing genetic data, health histories, and demographic details that were not fully protected by the company’s stated security protocols.
In response, 23andMe announced a comprehensive security overhaul, including the deployment of multi‑factor authentication, encryption of stored data, and a partnership with a third‑party cybersecurity firm to conduct regular penetration testing. Regulatory bodies in the United States and the European Union reviewed the incident, and the company has been required to provide affected users with free credit‑monitoring services and to notify them of the breach in accordance with GDPR and the California Consumer Privacy Act. The incident has prompted broader industry discussions about the adequacy of data protection measures for genomic information.
The company has reiterated its commitment to safeguarding consumer data and has pledged to enhance transparency around its privacy practices. While 23andMe remains a popular platform for ancestry and health insights, the 2023 breach has underscored the need for stricter security standards in the rapidly expanding field of consumer genomics.