iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› 23andMe Data Breach Victims Awarded $47 Million Payout by Bankruptcy Judge

23andMe Data Breach Victims Awarded $47 Million Payout by Bankruptcy Judge

A California bankruptcy court judge ruled that Chrome Holding, which acquired 23andMe after its bankruptcy, must pay $46.75 million to victims of a 2023 data breach that exposed personal and genetic data of up to 6.9 million people. The settlement will be distributed by Kroll Restructuring, with payment due within five business days.

iG
iGEN Editorial
July 8, 2026
23andMe Data Breach Victims Awarded $47 Million Payout by Bankruptcy Judge

Victims of a 2023 data breach at genetics testing company 23andMe are set to receive a multimillion-dollar payout after a California bankruptcy court judge ruled on Tuesday that Chrome Holding – which operates as TTAM Research Institute and is controlled by 23andMe co-founder Anne Wojcicki – must pay $46.75 million (£35 million) in compensation, according to a report by BBC Business.

The ruling stems from the 2023 data hack in which as many as 6.9 million people had their data breached. 23andMe compiles genetic profiles from DNA testing kits, including markers related to health and family history, making the exposed information highly personal. The breach began when hackers accessed roughly 14,000 user accounts directly, but because 23andMe offered family-tree features, the attackers were able to pull data on millions of relatives.

Settlement and Payment Mechanics

The judge’s order stipulates that Chrome Holding must pay the $46.75 million settlement within five business days from Tuesday, first to Kroll Restructuring, which is representing the victims. Kroll will then distribute the funds to affected individuals. The appointment of companies like Kroll is typical in corporate bankruptcy proceedings, the BBC noted. Representatives of Chrome Holding and 23andMe have been contacted for comment, though no response was reported.

Regulatory and Legal Fallout

The breach triggered investigations and fines. The Information Commissioner's Office (ICO), a UK watchdog, imposed a £2.31 million fine on 23andMe, stating the company had failed to put adequate security measures in place before the incident. In May, California Attorney General Rob Bonta sued the company after an investigation found that 23andMe "failed to take basic steps to protect users' data" and, according to Bonta, "lied to consumers about the severity of its 2023 data breach."

Company Background and Bankruptcy

Key Fact Detail
Original valuation $6 billion at its peak
Founded 2006
Went public 2021
Profitability Never turned a profit
Bankruptcy filing Early 2024 (about 18 months after the breach)
Acquisition Chrome Holding (Anne Wojcicki) won assets in bankruptcy auction with $305 million bid

The company filed for bankruptcy early last year and was acquired by Wojcicki’s Chrome Holding through a bankruptcy auction. Despite the breach and bankruptcy, 23andMe continues to operate and sell DNA testing kits online.

Implications for Enterprise Cybersecurity

While the 23andMe case involves consumer genetic data, the underlying failures highlight risks that enterprise technology leaders must address: inadequate security controls, insufficient access management, and failure to anticipate the cascading impact of a breach via interconnected user profiles. The breach exploited the family-tree feature – a reminder that any connected system can amplify the damage of an initial compromise. For supply chain and logistics firms handling sensitive partner data, the lesson is clear: enforce strict access limits, encrypt data at rest and in transit, and conduct regular third-party security audits. The scale of the settlement – nearly $47 million – also underscores the potential financial liability even for companies that have since been restructured or acquired.


Sources:

Keep Reading

Recommended Stories

Incogni Report Reveals Job-Search Platforms Selling User Data Without Awareness Technology

Incogni Report Reveals Job-Search Platforms Selling User Data Without Awareness

A new report from Incogni reveals that leading job-search platforms are selling users' sensitive data to third parties, often without users' awareness. ZipRecruiter, LinkedIn, and Monster rank highest for data collection and sharing. Only 7% of surveyed job seekers expressed concern about privacy risks.

June 15, 2026
Coupang Fined $400M by South Korea for Massive Data Breach Affecting 37.5 Million Users Technology

Coupang Fined $400M by South Korea for Massive Data Breach Affecting 37.5 Million Users

South Korea's data protection regulator fined Coupang $400M (624.68bn won) for a data breach affecting 37.5 million users, the largest such fine ever. The leak exposed names, contact, delivery details, and order histories. Coupang expressed regret and plans to challenge the decision; its CEO resigned.

June 14, 2026
Reverse-Lookup Service Exposed Millions of Photos of People's Faces Technology

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Independent security researcher Jeremiah Fowler found that the people-search service ClarityCheck left more than 9 million image files, including photos of faces, publicly accessible in an unsecured Amazon S3 bucket. A second misconfiguration exposed email addresses and phone numbers. The company secured the data after WIRED reached out but disputed that the data was publicly exposed.

August 19, 2026
Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files Technology

Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files

Hacker group Helix claimed it stole nearly one million Uber Freight files, and Uber Freight confirmed that someone accessed part of its systems without permission. The company says it contained and remediated the incident, but has not verified the files or disclosed what data was involved. Google Threat Intelligence Group links Helix to the UNC6671 extortion cluster targeting transportation firms.

August 13, 2026