Articles Tagged: Multistate Enforcement


23andMe’s $64.75M Breach Fallout Deepens With Multistate AG Deal

23andMe’s data-breach exposure grew again this week, as a coalition of more than 40 state attorneys general announced they will share in an additional $18 million resolution over alleged unreasonable security practices. The state deal follows a bankruptcy court’s approval of a separate $46.75 million settlement with private claimants, bringing the combined fallout to $64.75 million and underscoring how cyber incidents can trigger overlapping liability across private litigation, regulatory enforcement, and insolvency proceedings.

The underlying civil litigation has been centralized in the Northern District of California as IN RE: 23ANDME, Inc., Customer Data Security Breach Litigation, a multidistrict proceeding that has become a key docket for watching how courts handle privacy claims tied to alleged security failures involving highly sensitive consumer data.

FTC’s Amended Uber Complaint Signals Stronger Federal-State Pressure on Subscription Practices

The FTC’s lawsuit against Uber has taken on added significance with the agency’s announcement that participating states joined in an amended complaint, reinforcing a broader enforcement trend: consumer-protection cases involving billing, cancellation, and subscription design are increasingly being pursued through coordinated federal-state action.

For legal and compliance teams, that multistate posture matters.