23andMe Data Leak: Court Approves $46.75 Million Payout for Victims — What You Should Know

23andMe Data Leak: Court Approves $46.75 Million Payout for Victims — What You Should Know

A judge approved a $46.75 million payout for victims of the 23andMe data breach. Here’s who was affected, what data was stolen, and how you can better protect yourself online.

What Happened in the 23andMe Data Breach Case?

According to the BBC, a U.S. bankruptcy judge approved a $46.75 million payout for victims of the 2023 23andMe data breach.

Judge Brian Walsh approved the settlement on July 7, 2026.

Chrome Holding, which took control of 23andMe after its bankruptcy, must fund the settlement. Kroll Restructuring will then distribute the money to approved claimants.

The case shows how a data breach can continue affecting people years after the original attack.

Stolen personal information may remain useful to criminals for phishing, impersonation, and other fraud long after a breach leaves the headlines.

It is also worth remembering that your information may have been leaked in other breaches without you realizing it.

If you are not sure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What 23andMe Data Was Stolen?

The 2023 breach affected about 6.9 million 23andMe customers overall.

The U.S. settlement website says personal information linked to about 6.4 million U.S. residents was stolen.

The information varied by person.

It could include names, birth dates, sex, genetic information, predicted family relationships, ancestry reports, family tree details, and location information.

This information matters because criminals can use personal details to make phishing emails, fake calls, and impersonation attempts look more believable.

Genetic information is especially sensitive because it can reveal details about your ancestry, relatives, and health risks.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How Criminals Broke Into 23andMe Accounts

23andMe said criminals first gained access to about 14,000 accounts through credential stuffing.

Credential stuffing means trying usernames and passwords stolen in earlier breaches on other websites.

This often works when people reuse the same password for several services.

After entering those accounts, the attackers accessed information connected through 23andMe’s DNA Relatives and Family Tree features.

That allowed them to reach millions of additional profiles connected to the original accounts.

23andMe later required password resets and two-step verification, which asks for a second code during sign-in.