California Attorney General Files Lawsuit Against 23andMe Over 2023 Data Breach
The California Attorney General’s office announced a lawsuit on Thursday against Chrome Holding Co., the entity that succeeded 23andMe after the company filed for bankruptcy in March 2024. The filing claims that the former DNA‑testing firm failed to protect sensitive customer data during a 2023 breach that exposed genetic predispositions, ancestry information, and details about biological relatives for almost seven million users across the United States.
In the complaint, Attorney General Rob Bonta alleges that 23andMe did not take basic steps to safeguard user data, enabling a “credential stuffing” attack that leveraged passwords stolen in previous breaches, such as the 2017 MyHeritage incident. The attackers reportedly accessed roughly 14,000 accounts and accessed raw genetic data, health reports, DNA shared with relatives, and locations and birth years of relatives. The data subsequently appeared for sale on the dark web, with the poster specifically highlighting that the victims included Asian–Pacific Islander and Ashkenazi Jewish customers—a claim that Bonta described as “disturbing and incredibly dangerous” given ongoing anti‑Asian and antisemitic violence.
According to the lawsuit, 23andMe failed to promptly investigate anomalies such as a suspicious spike in login attempts in July and a Reddit post in August. The company only became aware of the breach in October when the stolen data was posted online, and the lawsuit asserts that the firm misled consumers about the severity of the incident.
The legal action seeks civil penalties, including injunctions to block future violations of California’s privacy laws. It also cites the California Genetic Information Privacy Act, which requires companies to obtain opt‑in consent from customers before selling their genetic information. The lawsuit contends that the sale of customers’ data proceeded without such consent, violating state law.
Beyond the state legal framework, the breach attracted international scrutiny. The UK’s Information Commissioner’s Office investigated the case, finding that 23andMe breached UK law by failing to implement appropriate authentication and verification measures during its login process. The ICO’s probe was conducted in coordination with Canada’s privacy commissioner. The company has since said it has “made several binding commitments to enhance protections for customer data and privacy.”
Industry experts note that the incident underscores the growing importance of robust cybersecurity practices, especially for companies handling highly sensitive personal data. With 23andMe having previously reached a $50 million settlement to resolve a class‑action lawsuit over the breach, the new lawsuit could further impact the company’s finances and its reputation for data security.
California’s attorney general office has indicated that the lawsuit is part of a broader effort to hold corporations accountable for safeguarding personal information and protecting consumer privacy. The case may set precedents for how genetic data companies are regulated under both state and federal statutes moving forward.
For now, Chrome Holding’s response remains pending, and the legal proceedings will likely unfold over the coming months. The lawsuit illustrates the complex intersection of technology, privacy law, and consumer protection in a rapidly evolving data‑driven landscape.