Arkansas Attorney General Tim Griffin announced Monday that the state is set to receive $431,937 as part of a proposed $18 million multistate settlement involving genetic testing company 23andMe over a 2023 data breach.
The proposed agreement, filed in federal bankruptcy court, would resolve claims brought by 42 states and the District of Columbia related to the cybersecurity incident that exposed personal information belonging to millions of consumers.
The settlement still requires approval from the bankruptcy court. A hearing on the agreement is scheduled for August 10th, and interested parties have until August 3rd to submit objections.
According to the settlement documents, Arkansas’ share of the funds may be used at the discretion of the Attorney General’s Office for purposes including consumer protection enforcement, consumer education, litigation, investigation and monitoring costs, or other lawful state purposes.
The agreement does not provide for direct payments to affected Arkansas consumers.
The case stems from a 2023 data breach in which 23andMe disclosed that information from approximately 6.9 million consumers was compromised, including more than 48,000 Arkansas residents, according to Griffin’s office.
The compromised information included customer data and, in some cases, genetic ancestry information.
The multistate claims were filed after investigations into the breach, with states alleging failures related to the protection of consumer data.
The proposed settlement would resolve those claims without 23andMe admitting wrongdoing.
23andMe filed for Chapter 11 bankruptcy protection in March 2025.
The company has since reorganized as a nonprofit organization.
As part of the proposed agreement, the reorganized company would face restrictions on its operations, including a five-year prohibition on direct consumer sales and limits on collecting or maintaining personally identifiable information, except when required for legal or bankruptcy-related purposes.
The settlement also follows a separate $46.75 million class-action settlement in bankruptcy court for eligible consumers who submitted claims by the February 2026 deadline.
The 2023 breach led to legal action from states across the country, with California’s claims handled separately and not included in the proposed agreement.
If approved, the settlement would resolve the participating states’ claims related to the cybersecurity incident and mark those bankruptcy claims as satisfied.


