Judge Greenlights $46.75 Million Payout to 23andMe Breach Victims as Company Navigates Bankruptcy Fallout

A federal bankruptcy judge approved a $46.75 million settlement for victims of 23andMe's 2023 data breach affecting 6.9 million customers. After prior payouts the net distribution reaches $32.46 million as the company works through Chapter 11 proceedings and parallel state enforcement actions. The ruling highlights ongoing tensions between bankruptcy protections and state privacy enforcement.
Judge Greenlights $46.75 Million Payout to 23andMe Breach Victims as Company Navigates Bankruptcy Fallout
Written by Dave Ritchie

A U.S. bankruptcy judge signed off this week on a $46.75 million settlement for victims of the 2023 data breach at genetic testing firm 23andMe. The decision brings partial closure to one of the most sensitive privacy incidents in recent years. Genetic data of nearly 7 million customers had spilled out. Personal details followed.

U.S. Bankruptcy Judge Brian Walsh in St. Louis called the deal fair and equitable. He said it served the best interest of a trust managed by the company’s bankruptcy administrator. Yet the payout shrinks. Some $14.29 million already went out in earlier distributions tied to the breach. That leaves an additional $32.46 million to flow to affected individuals. Short. Simple. But the numbers tell only part of the story.

23andMe, once a Silicon Valley darling that turned spit samples into ancestry reports and health insights, filed for Chapter 11 protection in March 2025. The breach. Waves of lawsuits. Stiffer competition. Shrinking demand for its kits. All of it converged. The Palo Alto company listed those pressures as reasons for seeking creditor protection, according to a Reuters report.

And the breach itself carried heavy weight. Hackers accessed genetic profiles, family trees, and other sensitive records. Customers learned their most private biological information might sit on the dark web. Trust evaporated. So did sales.

Last July a nonprofit controlled by 23andMe co-founder Anne Wojcicki stepped in. TTAM Research Institute paid $305 million for the company’s assets. The transaction offered a lifeline. It also complicated the legal mess still unfolding.

California Attorney General Rob Bonta filed his own suit over the breach. He accuses the company of ignoring early warnings that systems had been compromised. He claims executives downplayed the incident’s scale. Bonta wants civil fines that could reach millions. The case sits in San Francisco Superior Court against Chrome Holding Co., 23andMe’s legal name.

Judge Walsh has not yet ruled on a motion from the bankruptcy administrator seeking to halt California’s action. In a June 6 filing Bonta pushed back hard. He argued Congress never gave bankruptcy judges power to strip state courts of jurisdiction over state-law enforcement actions. Bankruptcy courts, he wrote, should not become “a haven for wrongdoers.” Bonta’s office offered no immediate comment when asked for updates.

The settlement approval arrives at a tense moment for the broader industry. Data breaches keep multiplying. Healthcare and consumer genetic firms sit in the crosshairs. Customers hand over DNA with the expectation of ironclad protection. When that promise breaks, fallout spreads fast. Regulatory scrutiny intensifies. Shareholder value collapses. Here, it helped drive a once-high-flying startup into bankruptcy court.

Recent cases show the pattern holds. In late 2025 Nebraska’s attorney general sued Change Healthcare, UnitedHealth Group and Optum after a massive ransomware attack. A state judge let the consumer protection and data privacy claims proceed after the defendants failed to dismiss them. The HIPAA Journal detailed how the court found Nebraska had alleged sufficient violations. Similar suits from other states have followed. Iowa’s attorney general brought her own action. Federal multidistrict litigation in Minnesota now consolidates dozens of class actions and provider claims stemming from that breach, which exposed data tied to roughly 190 million people.

Those incidents differ in scope. The Change Healthcare attack disrupted payments across the U.S. health system for weeks. Yet the core issues echo 23andMe’s experience. Companies collect vast stores of sensitive information. They promise security. When attackers succeed, victims and regulators demand accountability. Settlements follow. Fines accumulate. Executives testify before Congress.

But money alone rarely restores confidence. 23andMe customers who received early breach notifications described shock mixed with resignation. Their ancestry data, health predispositions, even relative matches sat exposed. Some worried about insurance discrimination or misuse by law enforcement. Others simply wanted the company to explain how it let the breach happen.

The bankruptcy adds another layer. Assets have moved to the Wojcicki-controlled nonprofit. The original corporate shell remains in Chapter 11. Victims receive payments from a trust. The California suit tests whether state enforcers can still pursue penalties against the restructured entity. Legal experts following the case say the outcome could shape how future privacy violations intersect with bankruptcy proceedings.

So far the settlement offers modest relief. After legal fees and prior distributions, individual payouts will vary. Many class members may see checks in the low hundreds of dollars. Hardly life-changing. Yet for some it represents recognition that their genetic code carried real value. And real risk.

Industry watchers note the decision also sends a signal. Bankruptcy does not erase data-privacy obligations. Judges still approve settlements that compensate victims. And attorneys general show no sign of backing down. Bonta’s office continues pressing its case even as the federal bankruptcy court moves forward.

23andMe’s story stretches back more than a decade. It popularized direct-to-consumer genetic testing. Millions bought kits during holiday seasons. Celebrities touted results on social media. The company raised billions. Then reality set in. Competition from larger players. Regulatory pushback on health claims. And finally the breach that exposed its weakest points.

Today the firm operates under new ownership. Its future remains uncertain. Demand for genetic testing has softened. Privacy concerns linger. The $46.75 million settlement closes one chapter. But questions about accountability, security standards, and the true cost of handling sensitive biological data will persist.

Other recent developments reinforce the stakes. A February 2026 analysis from Security.org noted that experts expect any global settlement in the Change Healthcare matter to dwarf previous healthcare breaches, potentially exceeding the $115 million paid by Anthem after its 2015 incident. No final agreement has been reached. Litigation continues. Providers and patients alike wait for resolution.

In the 23andMe case, the judge’s approval offers concrete relief for thousands of class members. It also underscores a harder truth. Once genetic data leaves secure systems, it cannot be recalled. The settlement mitigates harm. It does not erase the breach. Companies in this space now face higher bars for security. Customers demand more transparency. Regulators stand ready to enforce both.

Whether that leads to genuine improvements remains to be seen. For now, the $32.46 million still owed to victims will begin its journey through the trust. Checks will go out. Lessons, one hopes, will be absorbed. The genetic testing industry keeps evolving. Its privacy obligations must evolve faster.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us