Raleigh -- July 20, 2026: RALEIGH — North Carolina will receive more than $666,000 as part of an $18 million multistate settlement with genetic testing company 23andMe over its 2023 data breach, Attorney General Jeff Jackson announced.
The settlement follows an investigation that found 23andMe failed to adequately protect customers' sensitive genetic information after hackers gained access to customer accounts using stolen usernames and passwords. The breach affected approximately 6.9 million people worldwide.
“Your genetic data is the most personal data you have. 23andMe failed to protect it for millions of people, and when the breach happened, they pointed the finger at their own customers,” Jackson said. “So we held them accountable to make sure that the data is safe even if the company no longer exists.”
Investigators found that the company took months to detect the breach and did not have sufficient security measures in place to help prevent unauthorized access to customer data.
Following the breach, 23andMe filed for bankruptcy and sought to sell company assets, including customer genetic data. Jackson joined attorneys general from other states in legal action that prevented the sale of customers' genetic information without their consent.
Under the settlement, the company must implement stronger cybersecurity and data protection measures and continue to honor customers' rights to delete their genetic information.
North Carolina's share of the settlement totals more than $666,000. State officials have not announced how the funds will be used.
The settlement is part of a broader effort by states to hold companies accountable for safeguarding consumers' most sensitive personal information, particularly genetic data that cannot be replaced if compromised.

