The 23andMe Data Breach Settlement, Explained
The 2023 credential-stuffing breach affected about 6.9 million 23andMe users. Here is how the class action settled and how to check if you qualify.
In October 2023, 23andMe disclosed that attackers had used credential stuffing, recycled passwords from unrelated breaches, to gain access to a subset of customer accounts and to scrape data from the DNA Relatives feature. The breach ultimately affected approximately 6.9 million users. Class action litigation followed, and the cases were consolidated and settled, with the settlement reaching final court approval in 2025.
Timeline
October 2023: attackers used credentials from other breaches to log into 23andMe accounts that shared the same passwords. Through the DNA Relatives feature, they pulled profile data on accounts the compromised users had matched with, which is how a relatively small number of breached accounts became a much larger pool of affected profiles. Posts offering the data appeared on hacker forums in the weeks that followed.
Late 2023 and early 2024: 23andMe confirmed the scope. Roughly 5.5 million DNA Relatives profiles and approximately 1.4 million Family Tree profiles were affected, alongside the credential-compromised accounts themselves. Multiple class actions were filed in U.S. federal courts and consolidated.
2024 and 2025: the consolidated case moved through the standard sequence of motions, mediation, and a proposed settlement. Final approval and the start of the claims process followed, alongside the company’s separate March 2025 bankruptcy filing (see the 23andMe bankruptcy and your data).
What it means for your data
The data exposed in 2023 was not raw genome sequence files in the technical sense. What was scraped through DNA Relatives included names, profile photos where users had added them, relationship labels, and certain ancestry summary information for matched relatives. For some users, ethnicity estimates and other profile fields were included. Specific genotype data and raw DNA files were not the primary target of the scraping, per 23andMe’s notices and subsequent reporting.
That distinction matters but it has limits. Ancestry, profile, and relationship data tied to a real name is sensitive on its own and is not something a user can later un-publish. The settlement reflects that reality and provides eligible class members with relief options that typically include credit monitoring and, where applicable, cash payments. The exact amounts, eligibility criteria, and claims deadlines are set by the settlement and the claims administrator, not by us. Use the official settlement website (linked from the claims administrator and the court docket) to verify any number you see in secondhand coverage.
The breach also tightened the focus on credential hygiene as a genetic-privacy issue. 23andMe and several other testing companies subsequently required two-factor authentication for all accounts. If you tested before October 2023 and have not turned on 2FA, this is the single most useful step you can take on the consumer side.
What you can do
If you held a 23andMe account during the 2023 incident window, two things are worth doing as of early 2026.
Check the official settlement website to see whether you are a class member and whether the claims period is still open. Eligibility and deadlines come from the court-approved settlement, not from press coverage.
Tighten your account hygiene. Turn on two-factor authentication, change the account password to one you have not reused elsewhere, and review what you have elected to share through DNA Relatives. Our DNA testing privacy checklist walks through the full set of settings to review.
For the broader question of what testing companies can legally do with your data beyond a breach, see can DNA test data be sold and our side-by-side comparison of DNA test privacy policies. The genetic data privacy hub tracks the rest of the landscape.
Sources
- 23andMe customer notice on the 2023 security incident — 23andMe (accessed 2026-04)
- Reuters reporting on the 23andMe class action settlement — Reuters (accessed 2026-04)
- Bloomberg reporting on 23andMe security and litigation — Bloomberg (accessed 2026-04)
- Settlement information published by the court-appointed claims administrator (verify on the official settlement website) — Court-appointed claims administrator (accessed 2026-04)
- FTC guidance on data breaches and privacy enforcement — U.S. Federal Trade Commission Primary (accessed 2026-04)