Proof Required Or Not: What The 23andMe Customer Data Security Breach Settlement Actually Needs

The short answer is that most 23andMe data breach claimants did not need to provide any proof of harm whatsoever.

The short answer is that most 23andMe data breach claimants did not need to provide any proof of harm whatsoever. For the basic and health information claims worth up to $165, the settlement administrator simply cross-referenced your Class Member ID against 23andMe’s own breach notification records. No documents, no receipts, no uploaded files. If you were notified by 23andMe that your data was compromised in the October 2023 cyberattack, that alone was enough to qualify for a payout. The only category that required actual documentation was the extraordinary claims tier, which covers out-of-pocket losses up to $10,000 and demands receipts, bank statements, or police reports to back up your expenses. This distinction matters because roughly 6.4 million U.S.

Residents were affected by the breach, and the vast majority of those people suffered no direct financial loss they could point to on a credit card statement. The settlement, now funded at up to $50 million after a revised deal was approved by U.S. Bankruptcy Judge Brian C. Walsh on January 20, 2026, was structured so that the bulk of claimants could file without jumping through documentary hoops. That said, the claim deadline of February 17, 2026 has now passed for most people, with a narrow exception for those who first received notice on January 5, 2026, who had until March 1, 2026. Below, we break down exactly what each claim tier required, who qualified for additional statutory payments, what happens next with the bankruptcy process, and why payments are still a long way off.

Table of Contents

What Proof Does the 23andMe Data Breach Settlement Actually Require From Claimants?

The proof requirements depended entirely on which tier you filed under. The basic and health information claims, capped at up to $165 per person, operated on a verification model rather than a proof-of-harm model. The settlement administrator checked your name, email, and Class Member ID against 23andme‘s internal records of who received breach notifications. If the records confirmed you were a customer between May 1, 2023 and October 1, 2023, lived in the United States during that window, and received a breach notice, you were in. No harm, no foul, no paperwork. Compare that to the extraordinary claims tier, where the burden shifts significantly.

If you spent money on identity repair services, purchased credit monitoring out of pocket before the settlement’s free monitoring kicked in, or incurred costs related to the breach like hiring a locksmith after identity theft, you could claim up to $10,000. But you needed reasonable documentation: credit card statements, bank statements, invoices, receipts, or police reports showing unreimbursed expenses directly connected to the cyberattack. Someone who paid $300 for a credit monitoring subscription and $150 for a new security system would need to produce those receipts and explain how the expenses tied back to the 23andMe breach specifically. This tiered approach is increasingly common in data breach settlements. Administrators know that requiring millions of people to dig up proof of harm would crater participation rates and leave settlement funds undistributed. By verifying eligibility through the company’s own records, the basic tier kept the process accessible while reserving stricter scrutiny for larger individual payouts.

What Proof Does the 23andMe Data Breach Settlement Actually Require From Claimants?

Who Qualified for the Extra Statutory Cash Payment and What Was Needed

Residents of four states had access to an additional layer of compensation worth roughly $100 on top of the basic claim. If you lived in Alaska, California, Illinois, or Oregon between May 1 and October 1, 2023, you were eligible for a statutory cash payment tied to those states’ consumer data protection laws. The only requirement was proof of residency in one of those states during the relevant period, not proof that the breach caused you any specific harm. This is worth understanding because these four states have some of the strongest data privacy statutes in the country. Illinois, for example, has the Biometric Information Privacy Act, which has driven some of the largest privacy settlements in U.S. history.

California’s Consumer Privacy Act similarly gives residents enhanced protections. The settlement recognized that residents of these states had additional legal rights that were violated, and compensated them accordingly without requiring a showing of damages. However, if you lived in one of these states but moved away before May 2023 or after October 2023, the timing mattered. The residency requirement was pinned to that specific five-month window. Someone who left California in April 2023 and moved to Texas would not have qualified for the statutory payment, even if they were a 23andMe customer during the breach period. The base claim would still apply, but the state-specific bonus would not.

23andMe Settlement Maximum Payout by Claim TypeBasic/Health Claim$165Statutory Claim (4 States)$100Extraordinary Claim$10000Free Monitoring (5yr Value)$1200Canadian Settlement (Per Person)$10.8Source: 23andMeDataSettlement.com and court filings (January 2026)

How the $50 Million Settlement Fund Grew From the Original $30 Million

The settlement did not start at $50 million. The original deal put $30 million on the table, which was already one of the larger data breach settlements in recent years on a per-claimant basis. What changed was 23andMe’s corporate trajectory. The company filed for bankruptcy, and in July 2025, a nonprofit led by former CEO Anne Wojcicki purchased 23andMe for $305 million. That acquisition freed up additional funds, and the settlement was revised upward by $20 million to reach the $50 million cap. This is unusual. Most class action settlements shrink during bankruptcy proceedings, not grow.

Creditors typically fight over a diminishing pool of assets, and consumer claimants often end up at the back of the line. Here, the acquisition injected enough capital that the bankruptcy court approved the enhanced settlement. Judge Brian C. Walsh granted final approval on January 20, 2026, in the Eastern District of Missouri, clearing the way for the claims process to move forward under the case name *In re: 23andMe, Inc. Customer Data Security Breach Litigation*. For claimants, the practical effect is that per-person payouts could be meaningfully higher than originally projected. With 6.4 million affected individuals but far fewer expected to actually file claims, the math works in favor of those who submitted paperwork before the deadline. Whether the full $50 million is distributed depends on how many valid claims were filed and how the bankruptcy reconciliation process plays out.

How the $50 Million Settlement Fund Grew From the Original $30 Million

What Free Monitoring Services You Get Even Without Filing a Claim

One of the more practical benefits of this settlement requires no claim form at all. Every class member, whether they filed a claim or not, is automatically enrolled in five years of identity theft protection, dark web monitoring, and a specialized service the settlement calls Privacy & Medical Shield plus Genetic Monitoring. That last piece is notable because it specifically addresses the unique nature of genetic data, which unlike a credit card number cannot be changed or reissued. The tradeoff here is straightforward. If you filed a claim, you stood to receive a cash payment of up to $165 for basic claims, potentially $100 more for statutory claims if you lived in the right state, and up to $10,000 for documented extraordinary losses. If you did not file, you still get the monitoring services but no cash.

Given that credit monitoring services typically cost $10 to $30 per month on the open market, five years of coverage has a retail value somewhere in the range of $600 to $1,800, depending on the service tier. That is not nothing, even if it is not cash in hand. The genetic monitoring component is particularly relevant. Traditional identity theft monitoring watches for misuse of Social Security numbers, credit applications, and financial fraud. Genetic monitoring looks for unauthorized use of DNA data, which is a newer category of risk that most consumer protection products do not cover. For anyone whose genetic information was part of the 23andMe breach, this is a service that would be difficult to find and purchase independently.

Why Payments Are Delayed and What the Bankruptcy Process Means for Claimants

Even with final approval granted in January 2026, do not expect a check in the mail anytime soon. The settlement administrator has stated that payments will not be disbursed until 23andMe’s bankruptcy reconciliation process is resolved, and that process “is likely to take considerable time.” In bankruptcy cases, this kind of language typically means months, not weeks, and potentially longer if creditors contest distributions or if the reconciliation reveals complications. This is a limitation that frustrates claimants in virtually every bankruptcy-adjacent settlement. The court has approved the deal, the claims have been filed, and the money theoretically exists, but the mechanics of distributing funds through a bankruptcy estate involve additional legal steps. Creditors with higher priority may need to be paid first.

The settlement fund may need to be finalized based on the total number of valid claims received. Administrative costs come off the top. All of this takes time, and there is no firm date anyone can point to. If you filed a claim, the best course of action is to keep your contact information current with the settlement administrator through the official site at 23andMeDataSettlement.com. Settlement checks that bounce back due to outdated addresses are a common reason people miss payouts entirely. Watch for correspondence from the administrator and respond promptly to any requests for verification.

Why Payments Are Delayed and What the Bankruptcy Process Means for Claimants

The Separate Canadian Settlement Covering 300,000 Citizens

The 23andMe breach was not limited to U.S. customers. A separate $3.25 million Canadian settlement covers approximately 300,000 Canadian citizens whose data was compromised in the same October 2023 cyberattack. The Canadian deal operates under its own terms, filing deadlines, and distribution process, so affected Canadians should not assume the U.S. settlement details apply to them.

This is worth noting for dual citizens or people who maintained 23andMe accounts while living in both countries. The U.S. settlement specifically covers U.S. residents, and the Canadian settlement covers Canadian citizens. If you fall into both categories, the specific eligibility rules for each settlement determine which one, or potentially both, you could have filed under.

What the 23andMe Settlement Signals for Future Genetic Data Breach Cases

The 23andMe settlement is likely to serve as a template for how genetic data breaches are handled going forward. The tiered proof structure, where basic claims require no documentation but larger claims demand receipts, is becoming standard in data breach litigation. But the genetic monitoring component is new territory. As more companies collect DNA data for health, ancestry, and research purposes, the question of what happens when that data is stolen will only grow more pressing.

The fact that this settlement survived a bankruptcy proceeding and actually increased in value is also significant. It suggests courts are willing to prioritize consumer breach victims even when a company is financially distressed, particularly when an acquisition injects fresh capital. For the millions of people who trusted 23andMe with some of the most personal data imaginable, the settlement offers real, if delayed, compensation. For the broader legal landscape, it sets expectations for what genetic data breach accountability looks like.

Frequently Asked Questions

Did I need to upload any documents to file a basic claim in the 23andMe settlement?

No. For basic and health information claims worth up to $165, the settlement administrator verified your eligibility using your Class Member ID and 23andMe’s breach notification records. No documents, receipts, or proof of harm were required.

Who was eligible for the additional statutory cash payment of around $100?

Residents of Alaska, California, Illinois, or Oregon who lived in one of those states between May 1, 2023 and October 1, 2023. The payment was based on those states’ data privacy laws and required only proof of residency, not proof of harm.

What kind of proof was needed for extraordinary claims up to $10,000?

You needed reasonable documentation of unreimbursed out-of-pocket expenses caused by the breach. Accepted documents included credit card statements, bank statements, invoices, receipts, and police reports showing costs tied to the cyberattack.

When will settlement payments actually arrive?

No specific date has been set. The settlement administrator has said payments will not go out until 23andMe’s bankruptcy reconciliation process is resolved, which is expected to take considerable time. Keep your contact information current with the administrator.

Do I get anything if I did not file a claim before the deadline?

Yes. All class members are automatically enrolled in five years of free identity theft protection, dark web monitoring, and genetic monitoring services, regardless of whether they filed a claim.

Is there a separate settlement for Canadian customers?

Yes. A separate $3.25 million settlement covers approximately 300,000 Canadian citizens affected by the same breach. It operates under different terms and deadlines than the U.S. settlement.


You Might Also Like

Leave a Reply