Victims of a 2023 data hack at genetics testing company 23andMe are set to receive a multi-million-dollar payout from the firm.
The report indicates that victims of a 2023 data hack at genetics testing company 23andMe are set to receive a multi-million-dollar payout from the firm.
It further notes that a California bankruptcy court judge ruled on Tuesday that Chrome Holding, which last year took control of 23andMe after its bankruptcy, should pay out $46.75m (£35m) in compensation.
23andMe compiles genetic profiles of people through DNA testing kits, but it was heavily criticised after as many as 6.9 million people had their data breached in the 2023 hack.
Representatives of Chrome Holding and 23andMe have been contacted for comment.
Last year, Chrome Holding sold 23andMe’s assets to TTAM Research Institute, an entity operated by 23andMe’s co-founder, Anne Wojcicki. She won the company’s assets through a bankruptcy auction with a bid of $305m.
The ruling stated the settlement will be paid first to Kroll Restructuring, which is representing the victims, within five business days of Tuesday.
Kroll will then distribute the funds to the victims, the ruling said.
The appointment of companies like Kroll is typical in corporate bankruptcy proceedings.
The BBC has contacted the legal team representing the victims to ask how many people will receive the payout.
23andMe early last year filed for bankruptcy, about 18 months after hackers were able to access roughly 14,000 user accounts.
Because the company offered “comprehensive” genetic profiles of people who submitted their DNA, including genetic markers related to their health and family history, some of the information accessed by hackers was highly personal.
While the number of accounts accessed directly in the breach only represented a small fraction of 23andMe’s total users, the hackers were able to access the profiles of those users’ relatives. That gave them access to millions of profiles that 23andMe hosted.
The breach led to investigations and fines, including a £2.31m fine by the Information Commissioner’s Office (ICO), a UK watchdog.
The ICO stated 23andMe had failed to put adequate measures in place to secure sensitive user data prior to the incident.