LmCast :: Stay tuned in

California AG sues 23andMe over 2023 breach exposing health data

Recorded: May 29, 2026, 7 p.m.

Original Summarized

California AG sues 23andMe over 2023 breach exposing health data

News

Featured
Latest

California AG sues 23andMe over 2023 breach exposing health data

US charges Google security engineer with Polymarket insider trading

Charter Communications data breach affects 4.9 million accounts

GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

ChatGPT share links abused to host fake outage pages to deliver malware

California AG sues 23andMe over 2023 breach exposing health data

From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market

Dutch govt disrupts malware botnet with 17 million infected devices

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCalifornia AG sues 23andMe over 2023 breach exposing health data

California AG sues 23andMe over 2023 breach exposing health data

By Bill Toulas

May 29, 2026
02:08 PM
0

California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company’s failure to protect sensitive customer genetic and personal information.
Improper security led to a high-profile data breach in 2023 that exposed the sensitive information of nearly 7 million customers, including 855,541 Californians.
The incident came to light that year in October, after threat actors offered to sell a large number of records stolen from 23andMe, and leaked data samples (and later larger parts of the dataset) to prove the authenticity of the information.
The California-based company confirmed that the leaked data was genuine and claimed that it had been extracted following a credential-stuffing attack targeting accounts with weak credentials.
Soon, it became clear that the attackers had exfiltrated data from users opting into the platform's 'DNA Relatives' feature, and then accessed a second, much larger set of accounts that didn’t use the feature.
In total, the incident exposed data of roughly 6.9 million customers, including genetic data, health predisposition information, ancestry and ethnicity information, biological relatives, and DNA matches.
By the end of 2023, the company was already facing multiple lawsuits. In early 2024, national data protection authorities launched investigations that ultimately resulted in multi-million-dollar fines, leading the company to file for bankruptcy.
The latest lawsuit filed by AG R. Bonta claims that 23andMe failed to implement reasonable safeguards against credential-stuffing attacks, missed multiple opportunities to detect the intrusion, and failed to catch the coding error in DNA Relatives that led to the widespread breach.
In addition to the data protection failures, Bonta also underlines the misleading public statements 23andMe made before and after the incident.
Specifically, the firm claimed before the incident that its security met high standards. After the breach, it attempted to downplay the incident's severity, suggesting that the exposed data was largely public, and blamed customers for password reuse, stating that its systems had not been breached.
Overall, the Attorney General argues that these actions violated several state laws, including the California Genetic Information Privacy Act, the California Reasonable Data Security Law, the California Consumer Privacy Act (CCPA), the False Advertising Law, and the Unfair Competition Law.
The complaint seeks an injunction to prevent any further violations of the above, including the imposition of statutory penalties of $1,000-$7,500 per violation, depending on the case.
The AG announcement notes that the bankruptcy dispute regarding the proposed sale of Californians' genetic data and biological materials is a separate proceeding.

The Validation Gap: Automated Pentesting Answers One Question. You Need Six.

Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.This guide covers the 6 surfaces you actually need to validate.
Download Now

Related Articles:
GM agrees to $12.75M California settlement over sale of drivers’ dataDutch govt disrupts malware botnet with 17 million infected devicesCarnival Cruise confirms data breach affecting nearly 6 million peopleCharter confirms data breach after ShinyHunters extortion threat7-Eleven data breach exposes personal information of 185,000 people

23andMe
California
Data Breach
Lawsuits
Legal

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Charter confirms data breach after ShinyHunters extortion threat

Microsoft Defender can now automatically isolate hacked endpoints

Windows 11 KB5089573 update released with performance improvements

Sponsor Posts

33% Rise in Healthcare Credential Theft in 2025: What you need to know

#1 MSP Benchmark report 2026: Insights from 1,000+ MSPs on growth, security, artificial intelligence, and key 2026 trends.

AI is a data-breach time bomb: Read the new report

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The California Attorney General filed a lawsuit against 23andMe, now Chrome Holding Co., alleging the company failed to implement reasonable safeguards, resulting in a significant data breach in 2023 that exposed sensitive customer genetic and personal information. This incident involved approximately 7 million customers, including 855,541 Californians. The data exposure surfaced in October of that year after threat actors offered stolen records to prove authenticity. The company contended that the data exfiltration occurred via a credential-stuffing attack exploiting weak credentials. Investigation revealed that attackers accessed data from users who opted into the platform's 'DNA Relatives' feature, as well as a second, larger set of accounts that did not utilize that feature, resulting in the exposure of genetic data, health predisposition information, ancestry and ethnicity details, biological relatives, and DNA matches.

The lawsuit, brought by Attorney General Rob Bonta, asserts that 23andMe failed to establish adequate security measures against credential-stuffing attacks and missed opportunities to detect the intrusion. Furthermore, the complaint highlights a failure to identify and correct a coding error within the DNA Relatives feature that facilitated the widespread breach. Beyond the failures in data protection, the Attorney General also argued that 23andMe engaged in misleading public statements both before and after the incident, initially claiming high security standards and subsequently downplaying the severity of the breach and blaming customers for password reuse.

The Attorney General seeks an injunction to prevent further violations of state laws, arguing that these actions contravened several statutes, including the California Genetic Information Privacy Act, the California Reasonable Data Security Law, the California Consumer Privacy Act, the False Advertising Law, and the Unfair Competition Law. The complaint further seeks statutory penalties ranging from $1,000 to $7,500 per violation. The Attorney General noted that the dispute regarding the proposed sale of Californians' genetic data and biological materials remains a separate legal proceeding from the data breach claim. Bill Toulas, the reporter covering this matter, documented these developments.