Pennsylvania · verified official-source register

Pennsylvania Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Pennsylvania case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
not stated in the official release
Amount
$18 million; Pennsylvania's share: $491,902
Legal basis
No statutes or laws cited

Why the action was brought

23andMe’s 2023 data breach compromised genetic data and other customer information belonging to 6.9 million consumers worldwide, including 192,093 Pennsylvanians, with subsets published for sale on the dark web. Investigators found unreasonable security practices, including inadequate protections against credential stuffing, rate limiting, monitoring, investigation of unusual login activity, vulnerability remediation, and design testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Sabre Corporation

Date
not stated in the official release
Amount
$2.4 million settlement; Pennsylvania will receive $85,483.13, plus injunctive relief
Legal basis
No statutes or laws cited

Why the action was brought

Sabre’s SynXis Central Reservation System experienced a breach between August 2016 and March 2017 that exposed information from 1.3 million credit cards. The document states Sabre failed to protect customers’ private data. Hotel-provided consumer notices were delayed, with some issued as late as 2018, and some consumers received multiple notices.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Target Corporation

Date
not stated in the official release
Amount
$18.5 million settlement; Pennsylvania will receive $469,000; separate $10 million restitution fund
Legal basis
No statutes or laws cited in the document

Why the action was brought

On or about November 12, 2013, attackers used credentials stolen from a third-party vendor to access Target’s gateway server. Weaknesses allowed access to a customer-service database and malware installation, capturing names, contact details, payment-card information, and encrypted debit-card PINs. The breach affected over 100 million pieces of information nationwide, including 1.6 million Pennsylvania transactions.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.