A judge approved a $46.75 million payout for victims of the 23andMe data breach. Here’s who was affected, what data was stolen, and how you can better protect yourself online.
Table of Contents
What Happened in the 23andMe Data Breach Case?
The ruling is connected to the 2023 breach that affected nearly seven million 23andMe users. California officials previously said they planned to sue the company that took over 23andMe after the breach.
Attackers accessed highly personal information connected to 23andMe customers and their family networks. This type of data is sensitive because it can reveal private details about a person’s identity.
Judge Brian Walsh approved the settlement on July 7, 2026. Chrome Holding, which took control of 23andMe after its bankruptcy, must fund the settlement. Kroll Restructuring will then distribute the money to approved claimants.
The case shows how a data breach can continue to affect people years after the original attack. Stolen personal information may remain useful to criminals for phishing emails, impersonation attempts, and other fraud.
It is also worth remembering that your information can be leaked long before you notice anything wrong. It may later appear in phishing emails, fake calls, or fraud attempts that feel personal and convincing.
If you are not sure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce the risk of scams with simple, clear steps.
Who Was Affected and What 23andMe Data Was Stolen?
The 2023 breach affected about 6.9 million 23andMe customers overall. The U.S. settlement website says personal information linked to about 6.4 million U.S. residents was stolen.
The information varied by person. It could include names, birth dates, sex, genetic information, predicted family relationships, ancestry reports, family tree details, and location information.
This information matters because criminals can use personal details to make phishing emails, fake calls, and impersonation attempts look more believable. Genetic information is especially sensitive because it can reveal details about your ancestry, relatives, and health risks.
How Criminals Broke Into 23andMe Accounts
Regulators later found that the attacker directly accessed more than 18,000 23andMe accounts through credential stuffing. Credential stuffing means trying usernames and passwords stolen in earlier breaches on other websites.
This often works when people reuse the same password for several services. After entering those accounts, the attackers accessed information connected through 23andMe’s DNA Relatives and Family Tree features.
That allowed them to reach millions of additional profiles connected to the original accounts. 23andMe later required password resets and two-step verification, which asks for a second code during sign-in.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyWhat the 23andMe Breach Shows About Your Connected Data
The biggest lesson is that one reused password can affect far more than one account. In this case, the attacker directly entered about 18,000 accounts, but connected family features made information linked to almost 7 million customers reachable.
Your data can also be affected through another person’s account when a service connects profiles, relatives, or shared information. That is why unique passwords and two-step verification are so important.

3 Simple Ways to Protect Yourself After the 23andMe Data Breach
You cannot control every company that stores your information, but these habits can help reduce your risk:
1. Watch for messages about 23andMe settlement money
Be careful with emails, texts, or calls that promise a payout or ask you to confirm payment details. Criminals often use real settlements to make phishing messages look believable.
The claim deadline passed on February 17, 2026, so do not submit personal information through an unexpected link. Go directly to the official 23andMe settlement website to check the status of your existing claim.
2. Protect your main email account
Watch for password reset messages, new sign-in alerts, or security changes you did not make. Your email can be used to reset passwords for many other services, so it needs strong protection.
Use a unique password and turn on two-step verification, which asks for a second code during sign-in. Open your email account settings, choose Security, then look for Two-Step Verification or Two-Factor Authentication.
3. Be careful with messages using family or ancestry details
Watch for emails or calls that mention your relatives, ancestry, health reports, or DNA testing. Stolen details can make a fake message feel personal and trustworthy.
Do not click unexpected links or share more information. Contact the company or family member using contact details you already trust.
Your DNA Data Cannot Be Reset Like a Password
A password can be changed after a breach, but your genetic information stays with you. It can also reveal details about your relatives, which makes DNA data especially sensitive.
The bigger lesson is to stay alert after any data breach. Watch for personal messages, protect your email, and avoid reusing passwords across different websites.
Tools like Futureproof can help you spot leaks earlier and take clear steps before problems grow. Small, steady habits can give you more control and peace of mind when a company holding your data suffers a breach.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
