North Carolina · verified official-source register

North Carolina Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

North Carolina case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
Tuesday, July 14, 2026
Amount
$18 million multistate settlement; North Carolina’s share: $666,242
Legal basis
No statutes or laws cited in the document.

Why the action was brought

23andMe failed to adequately protect customers’ genetic and personal information, taking months to detect a 2023 credential-stuffing breach, failing to monitor unusual login patterns or fix security gaps, and initially blaming customers. The breach compromised 6.9 million customers worldwide, exposed genetic ancestry data, and led to stolen information being offered for sale on the dark web.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
2024-10-09
Amount
$52 million payment to states; North Carolina will receive $2,059,176
Legal basis
None stated

Why the action was brought

Marriott’s Starwood guest reservation database was compromised after intruders remained undetected from July 2014 through September 2018. The breach affected 131.5 million U.S. guest records and exposed contact information, gender, birth dates, loyalty, reservation, and stay-preference information, plus some unencrypted passport numbers and unexpired payment-card information.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Anthem

Date
2020-09-30
Amount
$39.5 million multistate settlement; North Carolina will receive $401,172.38
Legal basis
No statutes or laws cited in the document.

Why the action was brought

Beginning in February 2014, attackers infiltrated Anthem’s systems through malware installed via a phishing email and accessed its data warehouse. Anthem did not do enough to protect personal information, including names, birth dates, Social Security numbers, health care identification numbers, addresses, emails, phone numbers, and employment information, compromising 78.8 million Americans.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.