The Company Died and Your DNA Was an Asset

23andMe did not lose fifteen million genomes to a hacker. It listed them on a creditor's schedule. You can rotate a password. You cannot rotate a genome.

The Company Died and Your DNA Was an Asset

The failure most people prepare for is the breach. Someone gets in, data gets out, you change your password and watch your credit. It is a legible story with a villain, and the whole apparatus of consumer security is built around it. What happened to 23andMe between March 2025 and July 2025 was not that story. Nobody broke in. No exploit was published. The company simply ran out of money, and the genetic information of roughly fifteen million people became a line item in a Chapter 11 proceeding, valued, marketed, bid on in two auctions, and sold.

Call this custodial collapse. It is the failure mode where the entity holding your data does not get compromised; it ceases to exist in the form that made the promise. The data survives the promise. That asymmetry is the whole problem, and it is almost entirely absent from how people reason about handing over sensitive information.

THE CORE IDEA. A privacy policy is a promise made by a company. Bankruptcy is the legal process for dismantling a company and distributing what it owns. When those two things collide, the promise is an obligation to be negotiated and the data is an asset to be sold, and only one of them has a market value. You did not consent to the buyer. You consented to a seller that no longer exists.

What actually happened.

23andMe filed a voluntary Chapter 11 petition on 23 March 2025 in the U.S. Bankruptcy Court for the Eastern District of Missouri. Anne Wojcicki, the co-founder, resigned as CEO that day but stayed on the board. Joe Selsavage became interim CEO, Matt Kvarda came in as chief restructuring officer, and JMB Capital Partners committed $35 million in debtor-in-possession financing to keep the lights on through a court-supervised sale. The company's own press release carried the reassuring headline language: "No Changes to Customer Data Management and Access," and a commitment that "Any buyer will be Required to Comply with Applicable Law with Respect to Treatment of Customer Data."

Read that second line closely. It promises to obey the law, not to keep the original bargain. In the United States, no comprehensive federal statute governs what a bankrupt company may do with consumer genetic data. Compliance with applicable law was a low bar, and everyone in the room knew it.

The asset drew bidders. In May 2025, Regeneron Pharmaceuticals signed an asset purchase agreement at $256 million. In June, TTAM Research Institute, a California nonprofit public benefit corporation founded and led by Wojcicki, reopened the process with an unsolicited bid and won a second auction at $305 million on 14 June. Regeneron declined to go higher. Judge Brian Walsh approved the sale on 30 June 2025, and the transaction closed on 14 July 2025. The founder had bought the company, and the fifteen million genomes, back out of its own bankruptcy through a nonprofit she controls.

Judge Walsh, approving the sale, said the sale of genetic data is a scary proposition, and then noted that lawmakers had not prohibited it. That is the honest judicial summary of the entire episode.

The Bankruptcy Code is not completely silent here. Section 363 restricts the sale of personally identifiable information where the debtor's own privacy policy would forbid it, and section 332 lets the court appoint a consumer privacy ombudsman to advise on exactly that question. The court appointed Neil M. Richards, a law professor at Washington University, and his report, filed 11 June 2025, is the most useful document in the case file because it is the only place where the consent question was examined rather than assumed.

Richards found that he "cannot conclude with certainty that the sale of the Company's data in bankruptcy is otherwise consistent with its privacy policies, particularly for those customers who created their accounts before the 23andMe Privacy Statement was amended in 2022." The reason is a date. The word "bankruptcy" was not added to 23andMe's privacy terms until 8 June 2022. Customers who signed up before that consented to a document that did not contemplate this. They were notified of the amendment by a small "updated" banner on the website.

Even after the amendment, reaching the disclosure required either four correct clicks through a complex interface or scrolling through a 3,306-word document. Richards also noted that nearly a third of customers had not logged in during the previous three years, meaning they never encountered even the buried version. Meanwhile, the marketing surface said, prominently, that customers were "in control of your DNA" and that "your genetic data will not be shared."

That gap between the promise a customer perceives and the clause that actually governs is not an accident of this one company. It is the standard architecture of consumer consent. The bankruptcy just made it visible, because a bankruptcy court has to read the actual document.

Richards recommended that the buyer obtain "separate, affirmative consent from its customers in order to sell their data to either bidder." That recommendation was not adopted. Nobody was asked again.

KEY TAKEAWAY. Consent given to a company is not consent given to that company's assets in perpetuity. The entity you trusted can be liquidated, restructured, or acquired, and your data moves with the assets while your relationship with the original entity ends. Ask not "do I trust this company" but "do I trust whoever ends up owning this company's asset schedule."

On 10 June 2025, a coalition of more than two dozen states and the District of Columbia sued in the bankruptcy court to block the sale. Their argument was structural and correct: genetic information is categorically different from a mailing list, several states have genetic privacy statutes requiring express consent for transfer, and those statutes do not evaporate because the holder filed a petition. New York Attorney General Letitia James put it plainly: "23andMe cannot auction millions of people's personal genetic information without their consent."

What the states got was not consent. It was a set of negotiated conditions, Missouri Attorney General Andrew Bailey said, in exchange for dropping the objection. TTAM committed that genetic data would remain under the existing privacy policies with augmented cybersecurity, that consumers retain the right to permanently delete their data at any time with mechanisms to verify deletion, that any future resale would carry the same commitments forward, that data would not be shared with entities tied to designated countries of concern, that a three-person privacy advisory board with expertise in consumer privacy, bioethics, and cybersecurity would be created, and that TTAM would report on its privacy practices to the Missouri Attorney General on request.

Those are real commitments and they are better than nothing. They are also a substitution. The states asked for a consent requirement, which is a rule about who decides. They received governance undertakings, which are a set of promises by the buyer about how it will behave. Five states, California, Kentucky, Tennessee, Texas, and Utah, remained opposed at the time of approval.

The structural point survives the good outcome. This sale went to a nonprofit that publicly bound itself to the prior privacy terms in perpetuity. It could just as easily have gone to Regeneron, a pharmaceutical company with no direct-to-consumer genetics business, which is precisely the scenario Richards flagged as inconsistent with what customers thought they were agreeing to. The mechanism that decided which of those happened was a bidding war, not a consent process. Next time the high bidder may be less appealing, and the same mechanism will apply.

The 2023 breach, and why it is the same shape.

Two years before the bankruptcy, 23andMe showed another version of this problem.

Beginning in late April 2023 and continuing to October, attackers ran credential stuffing against 23andMe accounts, taking username and password pairs leaked from unrelated breaches and replaying them. The technique only works against reused passwords, and there was no mandatory multi-factor authentication in place. The joint investigation by the Privacy Commissioner of Canada and the UK Information Commissioner's Office found that more than 18,000 accounts were accessed this way. Most reporting, drawing on 23andMe's own disclosures, cites roughly 14,000. The discrepancy has not been cleanly reconciled in public, and it is worth flagging rather than smoothing over.

The other number matters. Through those compromised accounts, attackers reached the profile data of approximately 6.9 million people, roughly 5.5 million through the DNA Relatives matching feature and about 1.4 million more through Family Tree information. The overwhelming majority of those people had strong, unique passwords. Their accounts were never touched. They were exposed because they were genetically linked to someone whose account was.

A ratio of roughly 14,000 to 6.9 million is not a security incident scaled up. It is a different category of event. The amplification factor is a designed product feature doing exactly what it was built to do. The UK ICO fined the company £2.31 million on 17 June 2025 over the handling of the breach, covering 155,592 UK residents, with Information Commissioner John Edwards calling it "a profoundly damaging breach that exposed sensitive personal information, family histories, and even health conditions." Canadian and UK regulators both found the safeguards inadequate, and identified three separate events during 2023 that collectively should have triggered detection well before October.

SparkForge has covered the relational dimension of genetic privacy before, in the piece on the Golden State Killer and GEDmatch, where the argument is that your relatives expose you whether or not you ever took a test. The 2023 breach is that principle in its security form. This piece is about something different and, in a way, more mundane: not the relatives, but the custodian. What happens when the party holding the data stops being the party that promised anything.

THE ONE-LINE LESSON. You can rotate a password. You cannot rotate a genome.

What deletion actually does

Between the bankruptcy filing and June 2025, roughly 1.9 million customers, about fifteen percent of the base, requested deletion. That figure came from interim CEO Joe Selsavage's testimony to the House Oversight Committee on 10 June 2025. It is a large, rational, and mostly informed response, and it is worth understanding precisely what it accomplished and what it did not.

Deleting a 23andMe account removes you from research going forward and discards your physical sample. The company's own privacy statement is explicit that the action "cannot be canceled, undone, withdrawn, or reversed." That is the good news. Now the limits, in the policy's own words.

First, some genetic information persists regardless. The policy states that "23andMe and/or our contracted genotyping laboratory will retain your Genetic Information, date of birth, and sex as required for compliance with applicable legal obligations, including the federal Clinical Laboratory Improvement Amendments of 1988 (CLIA), California Business and Professions Code Section 1265 and College of American Pathologists (CAP) accreditation requirements, even if you chose to delete your account." Clinical laboratory retention rules are not a loophole the company invented, but the effect is the same: deletion does not mean the genotype ceases to exist anywhere.

Second, and more important, deletion is not retroactive against research already done. The policy: "any Research involving your data that has already been performed or published prior to your withdrawal from 23andMe Research will not be reversed, undone, or withdrawn." Around eighty percent of 23andMe customers consented to research participation. In October 2023 the company signed a data licensing agreement with GSK worth $20 million upfront for de-identified summary data and analysis services, and GSK retained rights to drug discovery programs initiated from that work. Whatever flowed into a partner's pipeline is not reachable by a deletion request submitted in 2025. There is no recall mechanism for data that has already left, been aggregated, been analysed, or been built into someone else's intellectual property.

Third, deletion protects you prospectively against the custodian. It does nothing about copies already exfiltrated in 2023, which are on the open internet, permanently, in curated form.

The bill came due, and it was small

On 14 July 2026, 42 states and the District of Columbia announced an $18 million settlement of their claims against the 23andMe bankruptcy estate over the 2023 breach. A separate class action settled for $46.75 million, with a claims deadline of 17 February 2026. The attorneys general faulted the company for lacking password blocklists, multi-factor authentication, rate limiting, intrusion detection, and adequate breach monitoring, for learning of the breach months after the data was already circulating, and for initially blaming consumers for their own password habits.

Divide $18 million across 6.9 million people and the arithmetic is instructive. This is what the legal system can offer after custodial failure involving immutable data: money, distributed thinly, years later, from an estate that is bankrupt by definition. The genomes are still out there. They will still be out there in fifty years, and they will still describe the children of the people who were breached.

THE MINDSET SHIFT. Stop evaluating a data-collecting company by its current privacy policy and current management. Evaluate it by its worst plausible future owner. Every company you hand data to has a nonzero probability of insolvency, acquisition, or a change of control, and your data does not get a vote in any of those. The relevant question is not "is this company trustworthy" but "what is this data worth to a liquidator, and can I survive it being sold."

What to actually do with this

If you have a 23andMe account and want it gone, the mechanism is in Settings, under the section for deleting your account, which triggers a confirmation email you must act on. Do it if you want it done, and understand the limits above: your genotype persists in the lab record under CLIA and CAP retention rules, research already conducted or published stands, any data licensed to partners before you withdrew is not recoverable, and nothing recalls what was taken in 2023. Deletion is a forward-looking act. It reduces future exposure. It does not undo anything.

Also request deletion of the sample itself rather than only the account, and revoke research consent explicitly rather than assuming account closure covers it. If you live in a state with a genetic privacy statute, your attorney general's office is the enforcement channel that has actually produced results here, and it is worth using.

The broader habit is a single question to ask before handing any organisation data you cannot change later. Not "do I trust them," because you are being asked to trust a management team and a policy document that both have a shelf life. Ask instead: if this company were sold for parts tomorrow, what happens to this specific data, and could I live with the answer.

For most data, the answer is fine, because most data is revocable. You can change a password, close an account, get a new card number, move house. Immutable identifiers are the exception, and the list is short and worth memorising: your genome, your fingerprints, your face, your iris, your gait, your voiceprint. These are the things that cannot be reissued. For those, the custodian's balance sheet is part of your threat model, because the promise that protects them is only as durable as the corporate entity that made it, and corporate entities die all the time.

Fifteen million people learned that in a courtroom in Missouri, and none of them were asked.

Sources and further reading

The bankruptcy and the sale

The consent question

The 2023 breach

Deletion and research


A companion to the SparkForge piece on the Golden State Killer and GEDmatch, which covers the relational dimension of genetic exposure. This one covers the custodial dimension. Figures reflect the linked sources as published; where a number is disputed, both are given.

Subscribe to SparkForge

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe