:

23ANDME PAYS $18M FOR GENETIC DATA BREACH

SECURITY DESK1 MIN READ
THU, JUL 16, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Genetic testing company 23andMe has agreed to an $18 million settlement with 43 state attorneys general over failure to protect customer genetic data.

The settlement resolves allegations that 23andMe inadequately safeguarded sensitive genetic information. The company failed to implement reasonable security measures, leaving customer DNA profiles and ancestry data vulnerable to unauthorized access. The breach exposed millions of users' genetic information, raising concerns about privacy and data protection in the biotech industry. Regulators argued the company did not adequately warn customers about security risks or obtain proper consent for data handling practices. 23andMe operates one of the largest consumer genetic databases globally. The company has faced increasing scrutiny over data privacy practices as genetic testing becomes more mainstream. This settlement marks one of the largest penalties against a direct-to-consumer genetics company. The $18 million will be distributed among the states involved in the settlement. Additionally, 23andMe agreed to strengthen its security protocols and implement enhanced data protection measures going forward.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Norway is considering regulatory measures against camera-enabled wearable headsets, citing serious privacy concerns. The Nordic country aims to address risks posed by devices capable of covert recording.

JUST NOWIndustry Desk

Dropbox is notifying users of unauthorized account access resulting from an email verification vulnerability in Lenovo's identity system. Attackers exploited the flaw to create fraudulent Lenovo IDs and gain entry to Dropbox accounts.

1H AGOAI Desk

A California federal grand jury has indicted a Russian national for orchestrating a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.

4H AGOSecurity Desk

The FBI is investigating a newly launched dark web service called Nexus that claims to possess digital scans of over 153 million driver's licenses from US and Canadian residents. The service is actively selling the stolen identification data.

5H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.