
If you’ve read the headline — “Attorney General Tong leads a 42-state settlement over the 23andMe genetic data breach” — you already know the soundbite. What the soundbite hides is the real story, and it’s a story about bankruptcy law, not privacy law. Forty-two states filed claims asserting at least $100 billion in damages. They settled for $18 million. That’s not a rounding error. That’s the entire point of a Chapter 11 case, and understanding why the number collapsed that far is worth more than the headline.
So let me do two things here. First, walk through what actually happened to 23andMe and its customers. Second — and this is where most coverage stops short — explain the bankruptcy machinery that turned a $100 billion demand into an $18 million check, because that machinery is the thing that controls the outcome for every creditor, consumer, and state in a case like this.
The breach, in plain terms
In October 2023, 23andMe disclosed a data breach affecting 6.9 million customers worldwide, including 65,766 people in Connecticut. This was a “credential stuffing” attack: hackers took username-password combinations leaked from other breaches and simply tried them on 23andMe accounts, betting (correctly) that lots of people reuse passwords. When a login worked, the attacker got in. And because 23andMe had a feature called “DNA Relatives” that let users see profiles of genetic kin, compromising one account exposed data about many others.
The exposed information included genetic ancestry data. Subsets of it ended up for sale on the dark web.
The Connecticut Attorney General’s office led the multistate investigation and found a list of security failures that reads like a checklist of what not to do: no comparison of passwords against known-breached-password blocklists, no required multifactor authentication, inadequate rate limiting and intrusion prevention, no meaningful logging or monitoring, failure to notice a massive spike in login attempts, unremediated known vulnerabilities, and untested design features. There was also a pointed detail — 23andMe had a data-sharing partnership with MyHeritage, which had itself been breached years earlier, exposing credentials shared between the two sites.
The AG’s press release also made a point of the company’s conduct after the breach: 23andMe first denied a breach happened, then confirmed it, then initially blamed customers for reusing passwords and accepted no responsibility. That posture matters, because it’s the kind of thing regulators remember when they decide whether to pursue penalties.
Then the company went bankrupt — and everything changed
Here’s the pivot. On March 23, 2025, 23andMe filed for Chapter 11 bankruptcy. The moment a company files, the legal ground shifts under everyone who has a claim against it. A data-breach enforcement action outside bankruptcy is a fight between a regulator and a solvent defendant. A data-breach claim inside bankruptcy is just one more unsecured creditor standing in a very long line, fighting over a shrinking pot.
To understand why the states recovered pennies on the dollar, you need to understand a few core bankruptcy concepts. Let me build them up.
Chapter 11 and the “estate”
When a company files Chapter 11, everything it owns becomes the “bankruptcy estate.” The company (now the “debtor”) generally keeps operating and running things as a “debtor-in-possession,” but it does so under court supervision and owes fiduciary duties to its creditors. The whole case is a contest over how to divide the estate’s finite value among everyone the company owes.
The automatic stay
The instant the petition is filed, an “automatic stay” slams down. Lawsuits stop. Collection efforts stop. Regulators generally can’t just proceed with enforcement actions to grab money. Everyone has to come into the bankruptcy court and get in line. This is why the states couldn’t simply keep litigating their breach claims to judgment — the bankruptcy forum captured everything.
Proofs of claim and the bar date
To get paid anything, a creditor has to file a “proof of claim.” The court sets a deadline — the “bar date.” For governments, there’s a special “governmental bar date,” which here was September 19, 2025. Before that deadline, the states filed their proofs of claim, collectively asserting at least approximately $100 billion. (Connecticut and other states each filed multiple claim numbers.)
That $100 billion figure is a demand, not a recovery. In bankruptcy, anyone can assert a giant number. What you assert and what you collect are two very different things.
Secured vs. unsecured, and the priority ladder
This is the heart of it. Not all claims are equal. Bankruptcy pays creditors in a strict order of priority:
- Secured creditors — lenders with collateral (a lien on specific property) — get paid first out of that collateral.
- Administrative and priority claims — the costs of running the bankruptcy itself (lawyers, the trustee, certain taxes and wages) — come next.
- General unsecured creditors — everyone else, including these state penalty claims — come last.
- Equity holders — shareholders — get whatever’s left, which in an insolvent company is usually nothing.
The states’ breach claims were classified as general unsecured claims — specifically “Allowed Chrome General Unsecured Claims” in the plan’s terminology. That’s the back of the line. General unsecured creditors typically recover cents on the dollar, and only after everyone ahead of them is satisfied. The size of your asserted claim doesn’t move you up the ladder; a $100 billion unsecured claim and a $100 unsecured claim sit on the same rung.
The sale of the crown jewel — the customer data itself
The most valuable asset 23andMe had was the very thing at the center of the scandal: its database of customer genetic data. In the bankruptcy, that asset was sold. The buyer was TTAM Research Institute, a nonprofit formed by 23andMe’s founder and former CEO, Anne Wojcicki. It has since re-registered as the 23andMe Research Institute.
This is where bankruptcy did some genuinely useful privacy work. The sale terms baked in data-security obligations that, as the AG’s office noted, probably would have been part of a settlement with 23andMe if the company hadn’t gone bankrupt: enhanced security requirements, risk analysis, an advisory board, agreement to be bound by comprehensive privacy laws without exception, and continued consumer deletion rights. Both the settlement and the sale carve the new Research Institute out expressly — the releases “shall in no way apply to 23andMe Research Institute.” In other words, buying the assets did not buy a free pass on the entity going forward.
The plan, the “wind-down debtor,” and the trust
Chapter 11 cases resolve through a “plan of reorganization” (or here, more accurately, a plan of liquidation/wind-down). The court confirmed the plan on December 1, 2025, amended it December 5, and the plan’s “effective date” was December 5, 2025.
After confirmation, the operating company essentially ceased to exist in its old form. The entity was renamed Chrome Holding Co. (f/k/a 23andMe Holding Co.) and became the “Wind-Down Debtor” — a shell whose only job is to finish liquidating and distributing value. A Plan Administration Trust was created to run that process, with a trustee-like administrator holding “sole authority” to settle disputed claims. That’s why the settlement motion was filed by the Trust, not by “23andMe” as anyone thinks of it.
How $100 billion became $150 million became $18 million
Now the settlement itself makes sense. The stipulation, executed July 14, 2026, does something that looks strange until you know the vocabulary. It sets two different numbers:
- The claims are “allowed” at $150 million. “Allowed” means officially recognized as a valid claim in the case.
- But the actual cash “Recovery Amount” is $18 million, paid within ten business days of court approval, in full satisfaction of the claims.
Why two numbers? Because in a bankruptcy with limited funds and many competing creditors, the “allowed amount” establishes where you stand in the class of general unsecured creditors, while the negotiated cash payment reflects what the estate can actually afford to pay. The $150 million figure is essentially a settled valuation of the claim; the $18 million is the check. And the stipulation goes to unusual lengths to make sure nobody — not other creditors, not future litigants — can weaponize the $150 million number. It has no “evidentiary or precedential effect,” can’t be cited as a basis for liability against anyone, and automatically shrinks to $18 million if anyone tries to use it that way.
Connecticut’s slice of the $18 million is $887,729 — among the largest state allocations in the deal, behind only Texas ($1,266,860) and Florida ($1,111,206). The allocations track roughly to affected-population and negotiated formulas, and every state’s cut is itemized in Appendix A of the stipulation.
There’s also a non-monetary term worth flagging: the debtors are barred for five years from (a) direct consumer sales of goods and services and (b) collecting or maintaining personally identifiable information, beyond what the Trust must keep to do its job. That’s a meaningful structural restriction, not just a payout.
One notable holdout: California
California did not join. Throughout the documents, the “Signatory Governmental Claimants” are defined as every state that filed breach claims except California. California’s claims were carved out and handled under a separate “California Claims Determination Procedures” track. When you see a big multistate settlement with one conspicuous absentee, it usually means that state either wanted more, had a different statutory posture, or preferred to litigate its own path. Either way, California’s non-participation is a reminder that these coalitions are voluntary and a state can always go its own way.
The legal standard the court will actually apply
The Trust asked the bankruptcy court to approve the settlement under Federal Rule of Bankruptcy Procedure 9019, which governs court approval of compromises. This is worth understanding because it explains why courts rubber-stamp deals that leave creditors with pennies.
The court doesn’t ask “is this the best possible result?” The Eighth Circuit standard (this case is in the Eastern District of Missouri) is only whether the settlement is “fair and equitable and in the best interests of the estate” and doesn’t “fall below the lowest point in the range of reasonableness.” The judge does not hold a mini-trial or resolve the underlying factual disputes. The bar is deliberately low, because the entire purpose of settling is to avoid the cost and delay of litigating.
Courts weigh four factors (the “TMT factors,” from a 1968 Supreme Court case):
- Probability of success in the litigation;
- Difficulties in collection if you win;
- Complexity, expense, inconvenience, and delay of litigating; and
- The paramount interest of creditors and deference to their reasonable views.
Applied here, the Trust’s argument writes itself: the claims are complex and risky, litigating would burn the estate’s limited resources and delay distributions to everyone, and even a total victory might cost more than it’s worth. Against a $100 billion demand, paying $18 million now to make it all go away — with 42 sophisticated state attorneys general agreeing — is comfortably “within the range of reasonableness.” The court will almost certainly approve it.
The takeaways that matter beyond this case
For consumers: Bankruptcy is where liability goes to get cheap. Those 6.9 million people whose genetic data was exposed aren’t getting made whole. There’s a separate class-action settlement of $46.75 million for U.S. consumers who filed claims by February 17, 2026 — a real recovery, but modest when spread across millions of people and set against the sensitivity of the data. If you were a 23andMe customer and missed that claims deadline, you’re likely out of luck, which is the brutal lesson of bar dates: miss the deadline, lose the claim.
For anyone who ever has a claim against a company: File your proof of claim, watch the bar date like a hawk, and understand your priority. An unsecured creditor’s leverage is limited no matter how righteous the claim. The size of your demand is not the size of your recovery.
For businesses: This is what data-security negligence looks like on the far end. A company that couldn’t be bothered to require MFA or check passwords against known-breach lists ended up liquidated, its founder’s nonprofit buying back the data under a court-supervised set of privacy obligations, and 42 states splitting $18 million. Bankruptcy limited the damages — but the company still ceased to exist in the form its customers knew.
For Connecticut specifically: The state also passed a new genetic privacy law, effective October 1, 2026, giving residents control over genetic samples they hand to direct-to-consumer testing companies and imposing disclosure and consent obligations on those companies. That’s the forward-looking piece: the settlement addresses the past, the statute addresses the next 23andMe.


Leave a Reply