Illinois · verified official-source register

Illinois Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Illinois case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
July 14, 2026
Amount
$150 million in allowed claims for states; court-limited recovery of $18 million, including more than $500,000 for Illinois; separate $46.75 million class-action settlement
Legal basis
None stated

Why the action was brought

The 2023 credential-stuffing breach compromised data of 6.9 million customers worldwide, including nearly 200,000 Illinoisans, and exposed personal data and, in some cases, genetic ancestry information. Investigators alleged unreasonable security practices, including inadequate safeguards, rate limiting, monitoring, investigation of unusual logins, vulnerability remediation, and design-feature testing, causing data to reach the dark web.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Blackbaud

Date
October 05, 2023
Amount
$49.5 million payment to states; Illinois will receive $2.28 million
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s software contained contact and demographic information, Social Security numbers, driver’s license numbers, financial, employment, wealth, donation, and protected health information. It allegedly failed to implement reasonable data security, remediate known security gaps, and provide customers timely, complete, accurate breach information, exposing millions of consumers and potentially confusing customers about notification duties.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Anthem, Inc.

Date
September 30, 2020
Amount
$39,500,000.00 total; $1,729,378.56 to the Illinois Attorney General
Legal basis
State Consumer Protection Acts listed in Appendix A; State Personal Information Protection Acts and Security Breach Notification Acts listed in Appendix B; federal Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, and implementing regulations, 45 C.F.R. §§ 160, 162, and 164; Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505/1 et seq.; Illinois Personal Information Protection Act, 815 ILCS 530/1 et seq.

Why the action was brought

The investigation concerned a criminal cyberattack publicly announced February 4, 2015, after attackers used malware delivered through phishing to access Anthem’s enterprise data warehouse. Unencrypted names, birth dates, Social Security numbers, healthcare identification numbers, addresses, email addresses, phone numbers, employment information, and income data of approximately 78.8 million people were accessed.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.