23andMe, Inc.
The 23andMe, Inc., Customer Data Security Breach litigation was centralized before Judge Edward M. Chen in the Northern District of California in April 2024, consolidating claims arising from a 2023 breach in which attackers used credential-stuffing techniques — reusing passwords exposed in unrelated prior breaches — to access a subset of 23andMe user accounts, then used the platform's relative-matching features to access genetic and genealogical data belonging to a much larger population of users connected to those accounts. With 41 pending actions, this docket presents a structurally distinctive claim population within the data-breach category.
What makes this docket's resolution path distinctive is the two-tiered nature of the affected population: directly compromised account holders whose own credentials were accessed, and a larger group of individuals exposed indirectly through genetic relative-matching connections to a compromised account. That structure raises novel questions about the scope of a data holder's duty to secure not just direct account data but also inferentially connected data about non-account-holder relatives, an issue with limited established precedent compared to more conventional data-breach fact patterns.
The sensitivity of genetic data — permanent, family-implicating, and increasingly relevant to insurance, employment, and identity contexts — makes this docket a notable test case for how courts will treat harm and damages theories specific to genetic-data exposure, an emerging question relative to the more established frameworks for financial or contact-information breaches. Criterica Intelligence's platform tracks this kind of emerging, sensitive-data-category litigation across the MDL landscape, since novel harm theories can meaningfully affect a docket's resolution timeline relative to more standardized data-breach claims. A companion capital brief on this docket is available through Criterica Capital.
Attackers used credential-stuffing techniques — reusing passwords exposed in unrelated prior breaches — to access a subset of 23andMe user accounts, then leveraged the platform's relative-matching features to access genetic data belonging to a much larger connected population.
Because the affected population includes both account holders whose own credentials were directly compromised and a larger group of individuals exposed only through their genetic connection to a compromised account.
The scope of a data holder's duty to secure not just direct account data but also inferentially connected data about non-account-holder relatives — an issue with limited established precedent.
Because harm and damages theories specific to genetic-data exposure are still developing relative to the more established frameworks for financial or contact-information breaches, which can affect this docket's resolution timeline.
Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.