Attorney Advertising · Informational Only · Not Legal Advice · Editorial Policy

23andMe data breach settlement compensation for Vermont New Hampshire New York residents

In July 2026, 42 state attorneys general finalized an $18 million settlement with 23andMe, a genetic testing company, following a major October 2023 data breach that exposed the DNA information, ancestry data, and personal details of approximately 6.9 million users. Vermont residents (about 14,000 affected), New Hampshire residents, and New York residents (about 305,000 affected) were among those whose genetic data was compromised by hackers using stolen login credentials and exploited security gaps.

The settlement is not a direct-payment program—and affected residents cannot file new claims. A separate class-action settlement with a February 2026 claim deadline already closed, so most affected residents have no remaining compensation pathway. What the state settlement provides instead is oversight requirements for 23andMe and a foundation for new genetic privacy laws.

Table of Contents

What Happened to Users' Data

The New Hampshire Department of Justice confirmed that hackers infiltrated 23andMe's systems between April and September 2023 using credential stuffing—submitting leaked passwords from other data breaches to gain access. The Office of Vermont Attorney General documented that 23andMe lacked three standard security controls: multi-factor authentication, screening against breached password databases, and monitoring for unusual login patterns.

Once inside user accounts, attackers accessed genetic ancestry data and personal profile information. Some of this data was later sold on the dark web for $1 to $10 per record. Users who shared their genetic information with 23andMe's research database or enabled third-party access faced broader exposure.

The Closed Class-Action Settlement

A separate class-action lawsuit resulted in a $46.75 million settlement approved on July 7, 2026, but with a critical constraint: eligible residents had to submit claims by February 17, 2026. That deadline has passed.

Residents who filed before the cutoff could receive up to $10,000 per person and five years of genetic monitoring services; those who did not file before February are no longer eligible under that track. If you were affected and did not file a claim by February 17, 2026, no compensation pathway remains available through the class action.

What the State Settlement ($18 Million) Actually Does

The $18 million settlement reached in July 2026 is not a compensation fund for residents. Instead, it is a regulatory enforcement action split among 42 states—Vermont received $154,000, New Hampshire received $187,490, and New York received $705,000. These funds support state attorneys general offices and consumer protection initiatives; they do not distribute direct payments to affected residents.

What residents do gain is enforceable change. The settlement terms required 23andMe to implement mandatory multi-factor authentication, monitor for login anomalies, screen accounts against known breached passwords, establish an independent privacy officer, and honor residents' requests to delete their genetic data. These requirements now apply to 23andMe's operations and are court-supervised as part of its bankruptcy reorganization.

23andMe's Current Status and Court Oversight

23andMe filed for Chapter 11 bankruptcy in March 2025 and was purchased by founder Anne Wojcicki's nonprofit organization in July 2025 for $305 million. The company now operates under court supervision, with the state-mandated security and privacy changes incorporated into its operational requirements.

Bankruptcy restructuring means 23andMe must meet these new security standards to continue operating. If the company fails to comply, state attorneys general and bankruptcy monitors can pursue enforcement. However, this arrangement does not create new compensation for users—it establishes guardrails for future operations.

New Genetic Privacy Law in Vermont

In direct response to the breach, Vermont enacted Act 135 (the Genetic Data Information Privacy Act) in July 2026. This law requires companies like 23andMe to obtain express informed consent before collecting, using, or sharing genetic data and gives residents greater control over their genetic records. Similar protections are under review in other states, but Vermont's law is now the strictest standard in the affected region.

What Affected Residents Should Do Now

If you were notified that your data was part of the 23andMe breach and have not already claimed compensation through the class action: Affected residents have no remaining lawsuit-based compensation option, but the settlement's security mandates provide ongoing protection for future users and protect your ability to request data deletion.

  • Confirm the February 2026 deadline has passed; you cannot retroactively file.
  • Monitor your identity with the free or paid monitoring services offered by 23andMe (as part of the breach response).
  • Request deletion of your genetic data from 23andMe directly if you choose to discontinue your account; the company must now honor such requests under settlement terms.
  • Change your passwords for any other accounts using the same credentials you used with 23andMe.
  • Report suspicious activity on financial accounts or credit inquiries to credit bureaus and your bank immediately.

Frequently Asked Questions

Is there still a way to get money if I was affected by the breach?

No. The class-action settlement that provided up to $10,000 per person closed to new claims on February 17, 2026. The state settlement finalized in July 2026 does not compensate individual residents—it funds state enforcement and requires 23andMe to improve security.

What should I do with my 23andMe account if I was affected?

You can request permanent deletion of your genetic data from 23andMe, and the company must now comply under settlement terms. You can also use any free identity monitoring services offered as part of the breach response. Contact 23andMe's privacy support directly.

Does the settlement require 23andMe to do anything differently?

Yes. The settlement mandates multi-factor authentication, monitoring for unusual login patterns, password breach screening, an independent privacy officer, and respect for data-deletion requests. These changes are court-enforced.


You Might Also Like

Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com. Was your data exposed? Track active breaches at DataBreachRadar.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy.