June 11–12, 2026: Victims of the October 2023 23andMe data breach are set to share a $46.75 million payout fund after the genetic-testing company's bankruptcy plan administrator approved the distribution—building on final court approval of the class settlement in January 2026, according to Reuters and filings in Chrome Holding Co.'s Chapter 11 case.
What happened in the 2023 breach
23andMe disclosed unauthorized access beginning in October 2023. Attackers used credential stuffing—logging in with username/password pairs stolen from other sites—and then abused the DNA Relatives feature to scrape genetic ancestry data and profile information at scale. The company later forced password resets and added multi-factor authentication requirements.
Per 23andMe's public notices and Reuters reporting, compromised data included:
- Display names, usernames, and birth years
- Ancestry and ethnicity estimates
- DNA Relatives matches and relationship labels
- Family Tree profile information accessible through the feature
23andMe stated it did not believe raw genetic sequencing files or financial data were exposed in the incident, but the combination of genetic markers and family connections creates uniquely sensitive identity and health-inference risks that standard credit-monitoring packages rarely address.
Litigation consolidated customer claims nationwide. The breach also helped drive California Attorney General Rob Bonta's separate May 2026 enforcement suit against Chrome Holding Co., which remains pending in state court while bankruptcy proceedings continue in Missouri.
From $30M settlement to bankruptcy
The breach litigation produced a proposed $30 million class settlement in district court in September 2024. Before payouts could fully run their course, 23andMe filed for Chapter 11 bankruptcy in March 2025, citing breach-related litigation, falling consumer demand, and competitive pressure. The operating business was sold to a nonprofit controlled by co-founder Anne Wojcicki; the debtor entity was renamed Chrome Holding Co.
Bankruptcy complicated—but did not eliminate—the consumer settlement. The case moved to the U.S. Bankruptcy Court for the Eastern District of Missouri (Case 25-40976-357, Judge Brian Walsh). Key milestones:
- October 2025: Preliminary bankruptcy-court approval of the settlement framework.
- January 30, 2026: Judge Walsh granted final approval of the class settlement, authorizing a victim fund of $30 million to $50 million depending on claims volume and administration needs (23andmedatasettlement.com).
- February 17, 2026: Deadline for class members to submit claims passed; the administrator began reconciling submissions against bankruptcy estate resources.
- June 11, 2026: Plan administrator filed approval of a $46.75 million payout level—$3.25 million below the January maximum—calling it an equitable outcome that avoids further litigation given the company's financial condition (Reuters).
How the $46.75M breaks down
Reuters reported the administrator's filing as follows:
- $46.75 million total approved fund for breach victims under the bankruptcy plan
- $14.29 million previously disbursed in connection with the breach (administration, notice, and related costs), reducing the additional cash available for new victim payouts to roughly $32.46 million
- More than 255,860 claims resolved, with thousands still pending reconciliation at the time of the June filing
Trade press and court filings have noted that a substantial share of any large genetic-data settlement goes to claims administration—here handled by Kroll—because verifying extraordinary-loss documentation and matching class membership across millions of notices is expensive. That tension between headline fund size and per-person cash is common in mega-breach class actions, especially when a debtor is insolvent.
What class members can receive
The official settlement portal at 23andmedatasettlement.com describes several benefit tracks (exact amounts depend on valid claims and fund exhaustion):
Cash payments
- Extraordinary claims: up to $10,000 for documented out-of-pocket losses tied to identity theft, fraud, or breach-related harm
- Health-information claims: up to $165 for individuals whose health-related genetic data categories were implicated
- Statutory cash claims: approximately $100 for eligible class members who submit the simpler claim form
Non-cash monitoring
- Five years of Privacy & Medical Shield services
- Five years of Genetic Monitoring—a breach-specific offering reflecting the sensitivity of exposed ancestry and relatives data
Because the claim deadline has passed, individuals who did not file should review the settlement site's FAQ and administrator contact information for any residual procedures—do not rely on third-party "claim helper" sites that charge fees.
Why genetic breaches are different
Unlike a credit-card or SSN leak, exposed genetic and relatives data is effectively permanent: you cannot rotate your genome. DNA Relatives matches can reveal non-consensual family relationships, donor-conceived lineage, or predispositions inferred by third parties. That is why regulators and plaintiffs pressed for genetic monitoring rather than credit monitoring alone—and why California's parallel AG suit alleges 23andMe downplayed severity and ignored compromise warnings.
The bankruptcy sale to Wojcicki's nonprofit and rebranding as Chrome Holding Co. also illustrate how corporate restructuring can outpace consumer remediation: customers may still use a 23andMe-branded service while the bankrupt shell resolves legacy liabilities.
Who is in the class
The settlement class generally covers U.S. customers whose personal information was compromised in the October 2023 incident and who received notice under the court-approved program. If you received a postcard, email, or website alert from 23andMe about the DNA Relatives intrusion in 2023–2024, you were likely in the notice pool—even if you no longer maintain an active kit subscription.
Action items if you were affected
- Check claim status at the official settlement administrator site—not unsolicited texts or social-media ads.
- Enroll in offered genetic and privacy monitoring through the settlement channel if you qualified but have not activated benefits.
- Enable MFA and unique passwords on any DNA or health accounts; credential stuffing succeeds when passwords are reused.
- Consider limiting DNA Relatives exposure in product settings if you no longer want open matching.
- Watch for targeted phishing citing real ancestry percentages, relative counts, or kit IDs—criminals weaponize breach metadata in genetic-themed scams.
- Monitor the California AG case separately—regulatory fines and injunctive relief could add future obligations beyond this class settlement.
Canonical BreachHistory record
BreachHistory tracks the underlying 2023 credential-stuffing and DNA Relatives scrape separately from this 2026 bankruptcy settlement milestone: 23andMe 2023 breach — 6.9M accounts. Related enforcement: California AG suit vs. Chrome Holding Co. (May 2026).
Sources: Reuters, 23andmedatasettlement.com, 23andMe security notice, Reuters (Oct 2023), The Record.