MONTGOMERY, AL — Alabama Attorney General Steve Marshall joined a coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving state claims related to the company’s 2023 data breach that exposed the personal information of millions of customers.
The settlement allows for $150 million in claims by participating states. However, because of the limited funds available in the bankruptcy estate and competing claims, the coalition will recover a total of $18 million, which will be distributed immediately. Alabama’s share of the settlement is $260,817.
The settlement follows a 2023 cybersecurity incident in which 23andMe reported that approximately 6.9 million customers worldwide had been affected, including 69,950 Alabama residents. According to the Attorney General’s Office, the breach exposed customer information, including genetic ancestry data in some cases, with portions of that information later appearing for sale on the dark web.
In a statement, Marshall said the settlement represents progress but does not excuse the company’s handling of consumer data.
“Last fall, we advised consumers to delete their accounts with 23andMe due to lack of accountability discovered within the tech company. While this settlement is a giant step in the right direction to begin to hold 23andMe accountable, it does not justify their actions,” Marshall said. “Protecting consumer data, especially that of personal genetics should be the highest security priority for these companies and the Attorney General’s Office will continue to ensure that Alabama law is complied with and that no more consumers face this exploitation.”
According to the multistate investigation, attorneys general found that 23andMe failed to implement several basic cybersecurity safeguards. Investigators alleged the company did not adequately protect against credential stuffing attacks, failed to require multifactor authentication, lacked sufficient logging and monitoring systems to detect suspicious activity, did not properly investigate unusual login patterns, failed to address known vulnerabilities, and did not sufficiently review or test certain design features.
The investigation also found that 23andMe learned of the breach months after customer information had become publicly available. State officials said the company initially denied a breach had occurred before later attributing the incident to customer password practices.
In March 2025, 23andMe filed for bankruptcy protection. During the bankruptcy proceedings, the company’s assets, including its consumer data, were sold to TTAM Research Institute, a nonprofit established by 23andMe founder and former CEO Anne Wojcicki. The organization has since been renamed the 23andMe Research Institute.
As part of the sale, the new owner agreed to enhanced data security measures, including conducting risk analyses, establishing an advisory board, complying with comprehensive privacy laws, and continuing to provide consumers with the ability to delete their data.
Separately, 23andMe also agreed to a $46.75 million class-action settlement to compensate affected U.S. consumers who submitted claims by the Feb. 17, 2026, deadline.
The settlement announced this week includes attorneys general from Alabama, Alaska, Arkansas, Arizona, Colorado, Connecticut, Delaware, the District of Columbia, Florida, Georgia, Idaho, Iowa, Illinois, Indiana, Kansas, Kentucky, Louisiana, Massachusetts, Maryland, Maine, Michigan, Minnesota, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Vermont, Washington, Wisconsin and West Virginia.






