Hackerii au folosit un atac de tip „credential stuffing” pentru a obține acces la conturile 23andMe în octombrie 2023.
Genetic testing company 23andMe was struck by a prolonged data breach that allowed hackers to gain personal data for about half of the company’s 14 million customers. Since then, 23andMe has struggled, filing for bankruptcy in March 2025 and eventually being acquired by Regeron. Now that the ownership situation has been settled, the company has begun allowing customers to file claims for their shares of the legal settlement related to that data breach.
Compania cu sediul în San Francisco, care permite oamenilor să trimită materiale genetice și să obțină o imagine de ansamblu asupra strămoșilor lor, anunțat in October 2023 that hackers had accessed customer information in a data breach. As a result, a January 2024 lawsuit accused the firm of not doing enough to protect its customers and not notifying certain customers with Chinese or Ashkenazi Jewish ancestry that their data was targeted specifically. It later settled the suit for $30 million.
„Am semnat un acord de soluționare pentru o plată totală în numerar de 14 milioane de lire sterline ($30 milioane) pentru a soluționa toate reclamațiile SUA privind incidentul de securitate al credential stuffing din 2023”, a declarat un purtător de cuvânt al 23andMe pentru CNET. „Continuăm să credem că această înțelegere este în interesul superior al clienților 23andMe și așteptăm cu nerăbdare finalizarea acordului.”
A few months after that decision, there’s finally an official method available for you to make your claim and potentially get paid by 23andMe, in some cases as much as $10,000. Keep reading to get all the details you need, and for more, find out why T-Mobile settlement checks have been delayed and see if you’re able to claim a piece of Apple’s Siri privacy settlement.
How many people were affected by the 23andMe data breach?
The settlement could cover roughly 6.9 million 23andMe customers whose data was targeted in the leak. To qualify for the proposed settlement, 23andMe customers must also have been US residents on Aug. 11, 2023.
That 6.9 million number includes around 5.5 million customers of 23andMe’s DNA Relatives profiles, which lets people find and connect with genetic relatives. The other 1.4 million people affected by the breach used another service known as Family Tree, which predicts a family tree based on the DNA users share with relatives, 23andMe said.
How much money could I get as part of the 23andMe settlement?
At the top end, 23andMe has said that it will pay out up to $10,000 with an “Extraordinary Claim” to customers who can verify that they suffered hardships as a direct result of their information being stolen in the data breach that resulted in unreimbursed costs. This includes costs resulting from “identity fraud or falsified tax returns,” from acquiring physical security systems, or from receiving mental health treatment.
Residents of Alaska, California, Illinois and Oregon who were impacted by the breach can also apply for a payment as part of the proposed settlement, since those states have genetic privacy laws with damages provisions. The payments for these individuals are expected to be around $100, depending on how many people file for them, a settlement document said.
Also, a smaller subset of affected users whose personal health information was impacted by the breach will be able to apply for a payment of $100.
Infographic credit: Gianmarco Chumbe/CNET; Background image: Jason Doiy/Getty Images
Will the settlement include anything else?
Pe lângă aceste plăți, 23andMe va oferi utilizatorilor afectați, de asemenea, trei ani de serviciu de monitorizare a securității numit Privacy Shield, despre care declarațiile au descris că oferă „monitorizare substanțială a webului și a dark web-ului”.
Cum pot depune o cerere pentru înțelegerea 23andMe?
In order to file a claim electronically, you can do so using this official online portal from the Kroll Restructuring Administration. An additional online form is available if you would like proof of your claim sent to you.
Potential claimants can also download and print out hard copies of the formular de cerere şi proof of claim form if they wish to submit them by mail. If you’re planning to use this method, send your forms to one of the addresses listed on the official claims website. The deadline to make your claim is 14 iulie 2025.
For more, read this explainer on how class-action lawsuits work.