Nearly three years after one of the world’s biggest genetic data breaches, some victims of the 23andMe hack are set to receive compensation.
A US bankruptcy court has approved a $46.75 million settlement for eligible US customers affected by the 2023 cyber-attack.
The decision follows a £2.31 million fine issued by the UK’s Information Commissioner’s Office (ICO) in June 2025, after the regulator found that 23andMe had failed to put appropriate security measures in place before the breach.
The settlement applies to eligible customers in the United States and does not include UK users. However, people affected in the UK may still have rights under UK data protection law.
What happened in the 23andMe data breach?
In October 2023, cybercriminals gained access to around 14,000 23andMe customer accounts using a technique known as credential stuffing, where stolen usernames and passwords from previous data breaches are used to access accounts where people have reused the same login details.
Because 23andMe allows users to connect with genetic relatives, the attackers were then able to access information linked to approximately 6.9 million people.
The compromised information included names, locations, profile photographs, ethnicity, family trees and, in some cases, health-related reports. Although raw DNA data was not stolen, the breach exposed an extraordinary amount of deeply personal information.
A settlement for eligible US customers
In July 2026, a California bankruptcy court approved a $46.75 million settlement for eligible US customers affected by the breach. The settlement forms part of the company’s bankruptcy proceedings following the sale of its assets.
The court documents do not yet confirm how much each eligible claimant will receive, as this will depend on the number of valid claims and how the settlement fund is distributed.
What does this mean for UK users?
The settlement approved by the US court does not include UK customers.
However, UK data protection law also gives people important rights when organisations fail to protect their personal information.
Following an investigation, the ICO concluded that 23andMe breached UK data protection law by failing to implement appropriate security measures before the attack.
These included not requiring multi-factor authentication, failing to enforce stronger password requirements and not introducing additional verification before users could access highly sensitive information.
That finding could be relevant if affected UK customers pursue legal action.
Why this case matters
Most data breaches involve information such as email addresses, passwords or payment details.
This case was different.
Genetic information, health reports and family relationships are among the most sensitive types of personal data a company can hold. Unlike a password or bank card, your genetic information cannot simply be replaced after a breach.
The ICO has made it clear that organisations handling this type of information are expected to meet particularly high security standards. The size of the fine, combined with the compensation approved for eligible US customers, sends a strong message that organisations can face significant consequences if they fail to protect sensitive personal data.
As the legal position develops, we’ll continue to report on any potential routes to compensation for UK users.
Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.