Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data
California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data
NEWS

California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

California Attorney General Rob Bonta filed a lawsuit against 23andMe — now Chrome Holding Co. — over its failure to protect millions of customers'...

Dylan H.

News Desk

May 29, 2026
6 min read

California AG Sues 23andMe Over Genetic Data Breach

California Attorney General Rob Bonta has filed a lawsuit against 23andMe — now operating under the name Chrome Holding Co. following its bankruptcy and acquisition — over the company's failure to adequately protect sensitive customer data in its 2023 data breach. The breach exposed genetic ancestry, health predisposition data, and personal information belonging to approximately 6.9 million users.

The lawsuit marks one of the most high-profile legal actions taken against a consumer genomics company in the United States and underscores the growing regulatory attention on the unique risks posed by genetic data — information that cannot be changed, is inherently familial in nature, and carries permanent implications for those exposed.


What Happened: The 2023 Breach

DetailInformation
Company23andMe (now Chrome Holding Co.)
Attack methodCredential stuffing
Initial disclosureOctober 2023
Users directly compromised~14,000 accounts (credential stuffing)
Total records exposed~6.9 million (via DNA Relatives feature)
Data typesGenetic ancestry, health predispositions, display names, birth years, locations

The 2023 breach began as a credential stuffing attack, where threat actors used previously leaked username/password combinations to access approximately 14,000 23andMe accounts. The attacker then leveraged the platform's DNA Relatives feature — which allows users to see and share data with genetic relatives — to scrape data from the 6.9 million accounts connected to those initially compromised profiles.

The breach became particularly alarming because it disproportionately exposed Ashkenazi Jewish and Chinese heritage users, data that was specifically highlighted and offered for sale in threat actor forums. 23andMe disclosed the breach in October 2023, acknowledged the extent in December 2023, and ultimately entered bankruptcy proceedings in 2025.


What the Lawsuit Alleges

California's lawsuit against Chrome Holding Co. centers on several key failures:

1. Inadequate Security Measures

The complaint alleges that 23andMe failed to implement reasonable security practices to protect against credential stuffing, including:

  • Failing to require or enforce multi-factor authentication (MFA) for user accounts prior to the breach
  • Insufficient rate-limiting on login attempts
  • Failure to detect or respond to the large-scale credential stuffing campaign in a timely manner

2. Delayed Notification

The AG alleges that 23andMe was slow to notify affected customers and regulators, violating California's breach notification obligations under the California Consumer Privacy Act (CCPA) and the California Data Breach Reporting Law (Civil Code Section 1798.82).

3. Failure to Safeguard Sensitive Genetic Information

23andMe held among the most sensitive categories of personal data — genetic information — which is specifically protected under California's Genetic Information Privacy Act (GIPA). The lawsuit argues the company did not apply security controls commensurate with the sensitivity of the data it collected and retained.

4. Misleading Statements

The complaint further alleges that post-breach communications from 23andMe were misleading about the scope of the compromise and the company's security posture.


Why Genetic Data Breaches Are Uniquely Dangerous

Unlike passwords or credit card numbers, genetic data cannot be changed. Its exposure carries consequences that are:

  • Permanent — the information is immutable
  • Familial — genetic data reveals information about biological relatives who never consented to 23andMe's terms of service
  • Health-sensitive — predisposition data for conditions like cancer, Alzheimer's, and hereditary diseases
  • Identity-linked — ancestry and ethnic heritage data that can enable targeted discrimination or persecution
  • Insurance-impactful — despite GINA protections in the U.S., genetic data can affect life, disability, and long-term care insurance decisions

23andMe's Collapse and the Chrome Holding Acquisition

23andMe filed for Chapter 11 bankruptcy in March 2025 following years of financial losses and the reputational damage from the breach. The company's genetic database — containing samples from over 15 million customers — was subsequently sold to Chrome Holding Co. as part of the bankruptcy proceedings.

The acquisition raised immediate concerns from privacy advocates and regulators about who now controls one of the world's largest private collections of human genetic data and what commitments, if any, bind the new owner to 23andMe's original privacy policy promises.

California's AG specifically named Chrome Holding Co. in the lawsuit, seeking to hold the successor entity accountable for 23andMe's pre-acquisition failures and to ensure ongoing obligations to affected customers.


Regulatory and Legal Landscape

This lawsuit represents a significant escalation in genetic data privacy enforcement:

DevelopmentDescription
California CCPA actionFirst major state AG suit over a genomics breach
FTC attentionThe FTC has previously flagged genetic data companies for privacy risks
GIPA enforcementCalifornia's Genetic Information Privacy Act offers specific protections
Class actionsMultiple class-action lawsuits were filed against 23andMe following the 2023 breach
Congressional scrutinyThe breach prompted calls for federal genetic privacy legislation

What Affected Customers Should Know

If you were a 23andMe customer:

  1. Your data may have been exposed — check if your email was part of the breach via services like Have I Been Pwned
  2. You cannot un-expose genetic data — the information about your ancestry and health predispositions may now be in threat actor databases
  3. Monitor for targeted phishing — attackers who obtained your data may attempt highly tailored social engineering attacks
  4. Review data deletion requests — 23andMe allowed customers to request data deletion; Chrome Holding's handling of such requests should be monitored
  5. Watch for insurance and discrimination risks — consult legal counsel if you believe genetic data exposure has affected you materially
  6. Follow the lawsuit — outcomes may include notification requirements, credit monitoring offers, or monetary settlements for affected customers

Industry Implications

The 23andMe breach and subsequent lawsuit have broad implications for the direct-to-consumer genomics industry:

  • Consumer genomics companies hold data that is fundamentally different in risk profile from typical consumer services — the regulatory framework must reflect this
  • MFA enforcement should be mandatory, not optional, for accounts holding health or genetic information
  • DNA Relatives and social features create massive blast-radius risks where a small number of compromised accounts can expose millions
  • Bankruptcy proceedings that include genetic databases require specific legal safeguards for data subjects — existing bankruptcy law was not designed with genetic data in mind

Source: BleepingComputer

#Data Breach#23andMe#Genetic Data#Privacy#Legal Action#California#Healthcare

Related Articles

Hims & Hers Breach Exposes the Most Sensitive Kinds of

ShinyHunters exploited compromised Okta SSO credentials to breach the Hims & Hers Zendesk customer support platform, exposing treatment category data for...

5 min read

Cegedim Santé Breach Exposes 15.8 Million French Healthcare

A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...

4 min read

266,000 Affected by Data Breach at Radiology Associates of

Radiology Associates of Richmond has disclosed a cyberattack in which threat actors stole files containing names and protected health information belonging to.

5 min read
Back to all News