
Arkansas Attorney General Tim Griffin announced a multi-state settlement with the genetic-testing company 23andMe, following a massive 2023 data breach that exposed sensitive customer information. The state will receive $431,937 from the $18 million agreement reached by a coalition of 42 state attorneys general. Read more below.
The 2023 cyber security incident compromised the data of 6.9 million consumers, which included more than 48,000 residents in Arkansas. According to Griffin, the breached data exposed a wide range of customer details, including genetic ancestry information in some cases.
After initially denying the breach and blaming customers for how they set up their accounts, 23andMe subsequently filed for Chapter 11 bankruptcy protection in March 2025.
The $18 million settlement resolves claims from 42 states—excluding California—that sought damages related to the incident in the U.S. Bankruptcy Court for the Eastern District of Missouri. Under the agreement, Arkansas will allocate its $431,937 portion toward future consumer protection enforcement, consumer education, litigation, or other compensatory and remedial purposes permitted by state law.
In addition to the financial payout, the settlement imposes strict operational restrictions on 23andMe, prohibiting the company from engaging in direct consumer sales or collecting and maintaining personally identifiable information for the next five years.
Furthermore, 23andMe previously agreed to a separate $46.75 million class-action settlement in bankruptcy court to compensate affected U.S. consumers who submitted claims by February 17, 2026.
 • Saline County Events List •.
 • Get MySaline’s free newsletter •Â








