Massachusetts · verified official-source register

Massachusetts Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Massachusetts case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
7/14/2026
Amount
$18 million settlement; Massachusetts will receive $387,218
Legal basis
General consumer protection and privacy laws; Gen. L. c 111, § 70G

Why the action was brought

23andMe’s 2023 credential-stuffing breach compromised genetic data and other customer information for 6.9 million consumers worldwide, including at least 136,761 Massachusetts residents; some data appeared for sale on the dark web. Investigators found unreasonable security practices, including inadequate safeguards, login limits, monitoring, investigation of unusual patterns, vulnerability remediation, and testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Blackbaud

Date
2023-10-05
Amount
$49.5 million payment to states; Massachusetts will receive almost $900,000
Legal basis
Massachusetts Data Breach Notification Law; Massachusetts Data Security Regulations

Why the action was brought

Blackbaud’s 2020 ransomware event exposed contact and demographic information, Social Security numbers, driver’s license numbers, financial, employment and wealth information, donation history, and protected health information of millions of consumers. Blackbaud allegedly failed to implement reasonable security, remediate known gaps, and provide customers timely, complete, or accurate breach information, significantly delaying or preventing consumer notification.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Experian Data Corp. and T-Mobile

Date
11/07/2022
Amount
Experian: $13.67 million; T-Mobile: $2.43 million (the announcement also describes the T-Mobile settlement as $2.5 million); Massachusetts will receive over $625,000
Legal basis
State consumer protection laws, breach notification laws, including Massachusetts Data Security Regulations

Why the action was brought

The 2012 breach let an identity thief retrieve names, Social Security numbers, addresses, and/or phone numbers from Court Ventures’ database, while Experian Data Corp. failed to notify affected consumers. The 2015 breach exposed names, addresses, dates of birth, Social Security numbers, identification numbers, and related credit-assessment information of over 15 million applicants, including over 280,000 Massachusetts residents, through inadequate security practices.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.