On July 14, 2026, a coalition of 42 state attorneys general announced a $150 million settlement with the bankruptcy trustee for 23andMe, resolving a multistate investigation into the company's 2023 data breach that affected approximately 6.9 million customers. Because the resolution was reached in the context of ongoing bankruptcy proceedings, only $18 million in actual funds will be distributed among the participating states. Despite the reduced monetary recovery, the action carries significant implications for any business that collects, stores, or processes sensitive consumer information.

The investigation identified a series of specific security shortcomings at 23andMe, including the absence of credential stuffing protections, the lack of rate limiting on login attempts, and inadequate breach detection logging. By publicly naming these deficiencies, the participating attorneys general have effectively articulated a baseline of reasonable safeguards that companies handling sensitive personal data are expected to maintain. Regulators, plaintiffs' counsel, and courts are likely to treat these controls as minimum expectations when evaluating the adequacy of a company's information security program, particularly in industries that manage biometric, genetic, health, or financial data.

The enforcement action also underscores two broader trends. First, state attorneys general are increasingly willing to coordinate large multistate coalitions to investigate and resolve data security matters, resulting in enforcement outcomes that rival federal actions in scope and visibility. Second, the pursuit of claims against a bankruptcy trustee demonstrates that insolvency will not necessarily shield a company or its estate from state-level accountability. Companies experiencing financial distress after a security incident should therefore anticipate that regulatory exposure will continue through, and potentially shape, the bankruptcy process.

Businesses that handle sensitive consumer information should review their authentication controls, monitoring capabilities, and incident response practices in light of the specific deficiencies highlighted by the 23andMe matter. Boards and executive leadership should also consider how cybersecurity risk is documented, escalated, and disclosed, given the increasing likelihood of multistate scrutiny following any significant incident. Vendor management programs and cyber insurance coverage warrant similar reassessment.

This alert is provided for general informational purposes only and does not constitute legal advice. Clients should consult qualified counsel regarding their specific circumstances.