23andMe data breach settlement compensation for Vermont New Hampshire New York residents

Vermont, New Hampshire, and New York residents have access to settlement compensation from 23andMe's genetic data breach through multiple programs.

Vermont, New Hampshire, and New York residents affected by 23andMe’s 2023 genetic data breach now have access to compensation through a multistate settlement. Vermont will receive $154,000, New York will receive $705,000, and New Hampshire will receive $187,490 from an $18 million settlement secured by 42 states’ attorneys general.

This settlement addresses the breach that exposed genetic ancestry information for approximately 6.9 million consumers nationwide, including roughly 14,000 Vermonters. The settlement comes after 23andMe filed for bankruptcy in March 2025 following investigations into the company’s inadequate data security practices. Beyond the multistate settlement, affected consumers can also pursue claims under a separate $46.75 million class-action settlement in bankruptcy, though individual claims required submission by February 17, 2026.

Table of Contents

What Was Exposed in the 23andMe Data Breach and Who Was Affected?

The 2023 breach at 23andme exposed genetic ancestry information belonging to millions of customers. Attackers not only accessed this sensitive biological data but also attempted to sell it on the dark web, creating long-term privacy risks for affected individuals. The breach wasn’t simply a case of unauthorized access—the exposed information was actively being monetized by bad actors, turning a privacy violation into a tangible security threat.

Approximately 6.9 million consumers were impacted by the breach, with Vermont particularly affected. About 14,000 Vermonters had their genetic information exposed, making this breach one of the largest privacy violations in the state’s history. For context, this means roughly 2 percent of Vermont’s population had their ancestry data compromised in a single incident at one company.

How Does the Multistate Settlement Work and What Does It Cover?

The $18 million multistate settlement resulted from coordinated action by 42 state attorneys general who investigated 23andMe’s data security failures. Rather than awarding compensation directly to individual consumers, most of these settlement funds go to participating states for consumer protection purposes and enforcement. The individual state allocations—$705,000 for New York, $187,490 for New Hampshire, and $154,000 for Vermont—represent the first wave of relief from the breach.

This settlement type differs from direct compensation to victims. Instead, state attorneys general use settlement funds for consumer protection initiatives, restitution programs, or enforcement actions against companies that commit similar violations in the future. While individual consumers don’t receive direct payments from the multistate settlement itself, those who submitted claims in the separate class-action bankruptcy settlement stand to receive direct compensation if approved. This two-track approach means victims have access to relief through different mechanisms, but claiming benefits requires understanding which settlement applies to your situation.

What Is the Class-Action Settlement and Who Qualifies for Direct Compensation?

Beyond the multistate settlement, 23andMe agreed to a $46.75 million class-action settlement through its bankruptcy process. This settlement specifically targets affected U.S. consumers and offers direct monetary compensation rather than state-level allocation.

However, accessing these funds required submitting a claim by February 17, 2026—a deadline that has passed as of this writing. If you submitted a claim before the February 17, 2026 deadline, you may be eligible for compensation from this $46.75 million fund. The amount you receive depends on the severity of your exposure, how the claims administrator processes applications, and how many claims are submitted in total. For those who missed the deadline, relief options may be limited to state-level protections and any future regulatory actions, making the timing of this settlement particularly important for those who knew about the breach and acted quickly.

How Do State Attorneys General Use Settlement Funds to Protect Consumers?

When states receive settlement money like the $154,000 Vermont is receiving, the funds typically support ongoing consumer protection efforts. These dollars might fund investigations into other companies’ security practices, establish restitution programs for victims of similar breaches, or strengthen enforcement against businesses that fail to safeguard personal information. New York’s allocation of $705,000, the largest among the three states, provides significantly more resources for consumer protection than the smaller allocations in Vermont and New Hampshire.

The allocation amounts reflect state population size and the estimated number of affected residents in each state, but they don’t represent direct per-person payments. A Vermont resident won’t receive a check from the state’s $154,000 allocation simply by having lived in Vermont during the breach. Instead, these funds become public resources directed toward protecting all consumers from future breaches and security failures.

What Data Security Failures Allowed the Breach to Happen in the First Place?

Investigations revealed that 23andMe engaged in unreasonable data security practices despite the company’s initial denials of culpability. The company failed to implement industry-standard protections, used inadequate access controls, and didn’t maintain robust monitoring systems that could have detected the breach faster. These weren’t edge-case failures or sophisticated attacks that bypass even the best security—they were preventable lapses in fundamental data protection practices.

23andMe’s security shortcomings included insufficient password protections, lack of multi-factor authentication requirements, and inadequate monitoring for unauthorized access attempts. The company’s response after the breach was discovered also drew criticism; rather than taking full responsibility immediately, 23andMe initially disputed the extent of the harm and delayed transparency with affected consumers. For consumers who trusted 23andMe with genetic information specifically because they assumed the company would protect such intimate biological data, these security gaps represented a fundamental betrayal of that trust.

How Does Genetic Data on the Dark Web Create Ongoing Risks for Affected Consumers?

The fact that genetic ancestry data was published for sale on the dark web—rather than simply accessed by attackers—creates persistent privacy and safety risks. Unlike other breaches where stolen data might eventually be recovered or deemed valueless, genetic information never loses value to bad actors. Someone who buys your ancestry data today can use it for identity theft, health insurance discrimination, law enforcement tracking, or simply building a detailed profile on you for years to come.

Vermonters and other affected consumers face ongoing exposure even after the breach is “settled.” New Hampshire residents who had their genetic data sold to dark web buyers can’t simply close an account or change a password to restore privacy. This permanence makes the 23andMe breach particularly concerning compared to breaches involving passwords or credit card numbers that can be invalidated. Affected residents should consider identity theft monitoring services and increased vigilance for fraudulent insurance applications or legal claims made using their genetic information.

What Changes Is 23andMe Making to Prevent Future Breaches?

As part of the settlement and bankruptcy process, 23andMe has committed to implementing stronger data security practices going forward. The company must upgrade access controls, require multi-factor authentication, enhance monitoring systems, and implement other industry-standard protections it had previously neglected. However, these commitments are part of a bankruptcy restructuring, meaning the company’s future—and its ability to survive long-term with these enhanced protections—remains uncertain.

The settlement documents and bankruptcy court filings outline specific security improvements 23andMe must make, but ongoing compliance and enforcement depend on continued attorney general oversight. Consumers considering whether to use genetic testing services now should research any company’s security track record thoroughly before submitting DNA samples or ancestry information. The 23andMe breach demonstrated that even companies offering direct-to-consumer services didn’t automatically prioritize data security despite handling uniquely sensitive biological information.

Frequently Asked Questions

What is the deadline to file a claim for the class-action settlement compensation?

The deadline to submit claims for the $46.75 million class-action settlement was February 17, 2026. If you missed this deadline, you likely cannot recover direct compensation through this fund, though you may still have rights to compensation programs managed by your state attorney general.

How much compensation will I receive if I filed a claim by the deadline?

The amount depends on how the claims administrator processes your application and how many valid claims are submitted overall. The total $46.75 million will be divided among all approved claimants, so individual amounts vary. You can check the status of your claim through the settlement administrator’s website using your claim number.

What information was exposed in the 23andMe breach?

Genetic ancestry information and related genealogy data were exposed and published for sale on the dark web. The breach affected approximately 6.9 million consumers globally, including roughly 14,000 residents of Vermont.

How will my state use the settlement money it receives?

Vermont’s $154,000, New Hampshire’s $187,490, and New York’s $705,000 will be used for consumer protection initiatives, enforcement actions, and programs designed to protect residents from similar data breaches in the future. These are not direct per-person payments to residents.

What should I do if I believe my genetic data was sold on the dark web?

Monitor your financial accounts closely for fraudulent activity, consider identity theft protection services, and watch for suspicious insurance applications or legal claims made using your identity. Contact your state attorney general’s office if you discover unauthorized use of your genetic information or personal data.

Can I still take legal action against 23andMe separately from these settlements?

Individual lawsuits against 23andMe are generally barred by the class-action settlement unless you properly opted out before the settlement was approved. Check the settlement administrator’s website to confirm whether you are bound by the settlement or if you retained rights to pursue separate claims. —


You Might Also Like