California sues DNA firm over millions exposed in genetic data breach

May 28, 2026 · admin

California’s Attorney General has filed a lawsuit against Chrome Holding, the successor company to DNA testing firm 23andMe, following an investigation into a major security incident that exposed the genetic information of approximately 7 million users in 2023. Rob Bonta contends that 23andMe failed to implement basic security measures to protect sensitive customer data, such as genetic predispositions, risk factors, and details about biological relatives, ancestry and ethnicity. The lawsuit also asserts the company deceived customers about the severity of the breach. The case marks the latest regulatory consequence for the genetic testing company, which has faced global oversight and penalties since the incident, such as a £2.31 million fine from the UK’s Information Commissioner’s Office.

The breadth of the security failure

The breach happened through a so-called “credential stuffing” attack, a technique in which hackers leveraged passwords that had been compromised in previous, unrelated data breaches. The attackers deployed these compromised credentials to obtain unauthorised access to 23andMe accounts held by users who had reused the same passwords across various services. This method of attack is regarded as fairly basic, yet 23andMe’s neglect in deploying adequate security measures left millions of users at risk. The company did not utilise sufficient security verification processes during the sign-in procedure, a basic safeguard that could have prevented the unauthorised access.

The inquiry by California’s Attorney General revealed that 23andMe took insufficient steps to safeguard one of the most sensitive categories of personal data available. Under UK data protection regulations, genetic data is classified as a special category requiring enhanced protections and safeguards due to its highly sensitive nature. The breach’s impact extended beyond the United States, with the UK’s Information Commissioner’s Office confirming that personal information belonging to 155,592 British residents had been compromised. The global reach of the incident underscores the gravity of the security failure and the company’s responsibility to safeguard data across multiple jurisdictions.

  • Hackers utilised stolen passwords from earlier unrelated data breaches
  • 23andMe failed to put in place sufficient security measures
  • Approximately seven million users experienced exposure of genetic information on a global scale
  • Genetic data requires strengthened legal safeguards under current UK law

How hackers gained access to private details

The 2023 security incident that compromised the genetic data of approximately seven million 23andMe users was carried out through a fairly simple yet remarkably successful technique known as credential stuffing. Rather than utilising sophisticated hacking methods, attackers leveraged previously stolen credentials in earlier security incidents affecting other companies and platforms. These stolen credentials were then methodically attempted on 23andMe accounts, exploiting a common human behaviour: the sharing of passwords across multiple online services. This low-tech approach proved remarkably successful against 23andMe’s weak protective measures.

What constituted this attack especially destructive was the confidential quality of the data being accessed. Genetic information serves as one of the deeply private and immutable forms of data an individual can own, revealing disease susceptibilities, family heritage, ethnic background, and information about biological relatives. The breach was exacerbated when threat actors actively promoted the stolen data on the hidden networks, specifically highlighting that it originated with Asian American Pacific Islander and Jewish users. This targeted approach raised serious concerns about possible prejudicial treatment and personal dangers during a period marked by growing attacks against these groups.

Login credential misuse explained

Credential stuffing is a cyberattack method in which attackers automatically submit numerous pilfered account details to victim websites, wagering that individuals have duplicated the identical login information across various services. This method capitalises on typical user habits and inadequate password discipline rather than necessitating sophisticated expertise. Once hackers break into to an account through credential stuffing, they are able to extract the confidential details contained in. 23andMe’s failure to implement two-factor verification or supplementary security checks rendered accounts exposed to this relatively unsophisticated but highly effective attack vector.

International regulatory action and sanctions

The 2023 data breach has triggered considerable oversight attention across numerous countries, with regulators globally taking action against 23andMe for its neglect in properly securing personal genetic data. The company has faced particular criticism for failing to adopt fundamental protective safeguards such as multi-factor authentication and robust identity verification protocols. These failures proved catastrophic, permitting attackers to obtain millions of user accounts through comparatively basic methods. Regulators have emphasised that genetic data represents a distinct classification of individual records necessitating stronger security measures under privacy legislation, making 23andMe’s safeguarding shortcomings particularly serious.

The UK’s Information Commissioner’s Office (ICO) imposed a penalty of £2.31 million against the company, after an enquiry that revealed 155,592 UK residents’ data had been accessed during the breach. The ICO’s investigation, carried out jointly with Canada’s privacy commissioner, determined that 23andMe had violated UK data protection law by failing to implement suitable identity verification and security controls. The watchdog’s findings underscored widespread deficiencies in the company’s security architecture and its commitment to safeguarding customer privacy. Currently, California’s Attorney General has initiated proceedings against Chrome Holding, 23andMe’s parent organisation following the firm’s bankruptcy, claiming the predecessor company both failed to safeguard data but furthermore deceived consumers regarding how serious the breach was.

Jurisdiction Action taken
United Kingdom Information Commissioner’s Office fined 23andMe £2.31 million for failing to implement adequate security measures and protect 155,592 UK residents’ data
Canada Privacy Commissioner coordinated investigation with the UK ICO into 23andMe’s security failures and data protection violations
California, USA Attorney General Rob Bonta filed lawsuit against Chrome Holding, alleging predecessor 23andMe failed to protect customer data and misled consumers about breach severity

Wider implications for genetic data protection

The 23andMe breach and subsequent regulatory actions have revealed fundamental vulnerabilities in how genetic information is safeguarded across the industry. Genetic data represents one of the most confidential categories of personal data, exposing not only an individual’s health predispositions but also information regarding biological relatives and ancestry. The circumstance that stolen data was actively promoted on the dark web targeting Asian American Pacific Islander and Jewish users adds a deeply troubling dimension, illustrating how genetic information can be weaponised for discriminatory purposes during periods of heightened social tension and hate crimes.

The case has raised urgent questions about whether existing data protection frameworks are sufficiently robust to handle the distinctive risks associated with genetic information. Companies working within this space must now face heightened expectations from regulators globally, who are increasingly treating genetic data as demanding special category protections. The California lawsuit constitutes a significant escalation in enforcement action, indicating that regulators will not accept inadequate security measures or misleading communications about data breaches. This shift is likely to reshape industry standards and force genetic testing companies to commit significant resources in security infrastructure and transparency practices.

  • Genetic data needs special legal protections due to its sensitive and irreversible nature
  • Credential stuffing attacks demonstrate the critical need for multiple authentication layers and thorough checks
  • Dark web sales focused on specific ethnic and religious groups, prompting discrimination concerns
  • International compliance cooperation enhances enforcement against serious breaches of data safeguards
  • Companies must reconcile innovation with strong protections and clear incident disclosure

The company’s challenging route to insolvency

23andMe’s fall into financial distress represents a dramatic reversal of fortune for a firm that once held considerable investor support and high-profile backing. At its height, the company’s share price hit $300, and it drew high-profile customers such as Snoop Dogg, Oprah Winfrey, and Eva Longoria. The firm, founded by Anne Wojcicki—sister of the late YouTube boss Susan Wojcicki and former wife of Google co-founder Sergey Brin—had established itself as a leading player in bespoke genetic analysis. However, mounting operational challenges and reputational damage from the 2023 security breach severely damaged investor faith and consumer confidence.

The company’s insolvency proceedings in the previous year marked a critical turning point, forcing it to divest operations through a court-supervised process. This shift created additional complications for users, many of whom experienced problems deleting their accounts during the reorganisation phase. Concerns arose about possible information transfers to insurance companies, with users worried that their DNA data could be applied to reject claims or increase policy costs. The later rebrand as Chrome Holding constituted an attempt to distance the company from its problematic history, yet the enforcement consequences from the breach has grown increasingly severe, with authorities worldwide taking legal measures that threaten the long-term sustainability of operations.