A judge approved a $46.75 million payout for victims of the 23andMe data breach. Here’s who was affected, what data was stolen, and how you can better protect yourself online.
Table of Contents
What Happened in the 23andMe Data Breach Case?
Judge Brian Walsh approved the settlement on July 7, 2026.
Chrome Holding, which took control of 23andMe after its bankruptcy, must fund the settlement. Kroll Restructuring will then distribute the money to approved claimants.
The case shows how a data breach can continue affecting people years after the original attack.
Stolen personal information may remain useful to criminals for phishing, impersonation, and other fraud long after a breach leaves the headlines.
It is also worth remembering that your information may have been leaked in other breaches without you realizing it.
If you are not sure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What 23andMe Data Was Stolen?
The 2023 breach affected about 6.9 million 23andMe customers overall.
The U.S. settlement website says personal information linked to about 6.4 million U.S. residents was stolen.
The information varied by person.
It could include names, birth dates, sex, genetic information, predicted family relationships, ancestry reports, family tree details, and location information.
This information matters because criminals can use personal details to make phishing emails, fake calls, and impersonation attempts look more believable.
Genetic information is especially sensitive because it can reveal details about your ancestry, relatives, and health risks.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyHow Criminals Broke Into 23andMe Accounts
23andMe said criminals first gained access to about 14,000 accounts through credential stuffing.
Credential stuffing means trying usernames and passwords stolen in earlier breaches on other websites.
This often works when people reuse the same password for several services.
After entering those accounts, the attackers accessed information connected through 23andMe’s DNA Relatives and Family Tree features.
That allowed them to reach millions of additional profiles connected to the original accounts.
23andMe later required password resets and two-step verification, which asks for a second code during sign-in.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
