The 2023 cyberattack on genetic-testing company 23andMe became one of the most closely watched data-privacy cases of the year — and its settlement offers a clear look at how these claims work, and why deadlines matter so much.
What happened
23andMe announced on October 6, 2023 that attackers had accessed personal information in its databases. According to the official settlement website, the breach affected the data of approximately 6.4 million United States residents. A class action followed, and a settlement was reached with the company (since renamed “Chrome”).
Who the settlement covered
You were a Settlement Class Member if you:
- were a 23andMe customer at any time between May 1, 2023 and October 1, 2023;
- resided in the U.S. during that period; and
- received notice from 23andMe that your personal information was compromised.
What class members could receive
The settlement offered several types of benefits, including:
- Up to $10,000 for documented “Extraordinary Claims” (significant, verifiable losses tied to the breach);
- Up to $165 for Health Information Claims;
- an estimated $100 Statutory Cash Claim for eligible residents of certain states; and
- five years of Privacy & Medical Shield + Genetic Monitoring services.
The deadlines have passed — but there’s a lesson
The claim form deadline was February 17, 2026, and the opt-out and objection deadlines were December 29, 2025. Those windows have now closed. Class members who did nothing will not receive a cash payment, though the settlement noted they retained the opportunity to participate in the five years of monitoring services.
This is exactly why we track deadlines so closely. In data-breach cases — now the highest-volume category of consumer class actions — the difference between getting paid and getting nothing often comes down to filing a simple claim form on time. If your information has ever been exposed in a breach, watch for the official notice, and don’t assume a claim isn’t worth the few minutes it takes.