California sues DNA firm over millions exposed in genetic data breach

May 28, 2026 · admin

California’s top legal officer has launched legal action against Chrome Holding, the successor company to DNA testing firm 23andMe, following an investigation into a major security incident that exposed the DNA data of nearly seven million users in 2023. Rob Bonta contends that 23andMe failed to implement fundamental protective safeguards to protect private user information, such as genetic predispositions, risk factors, and details about biological relatives, ancestry and ethnicity. The lawsuit also asserts the company misled consumers about the severity of the breach. The case represents the most recent legal penalty for the genetic testing company, which has encountered international scrutiny and penalties since the incident, including a £2.31 million fine from the Information Commissioner’s Office in the UK.

The scale of the security breach

The breach happened through a so-called “credential stuffing” attack, a technique in which hackers exploited passwords that had been exposed in previous, unrelated data breaches. The attackers deployed these compromised credentials to gain unauthorised access to 23andMe accounts belonging to users who had reused the same passwords across multiple platforms. This method of attack is regarded as fairly basic, yet 23andMe’s neglect in deploying adequate security measures left millions of users vulnerable. The company did not utilise sufficient authentication or verification protocols during the sign-in procedure, a fundamental protection that could have prevented the unauthorised access.

The investigation by California’s Attorney General revealed that 23andMe failed to safeguard one of the most sensitive categories of personal data available. Under UK data protection regulations, genetic data is classified as a special category requiring heightened safeguards due to its highly sensitive nature. The breach’s impact extended beyond the United States, with the UK’s ICO verifying that personal information belonging to 155,592 British residents had been compromised. The global reach of the incident highlights the seriousness of the security breach and the company’s responsibility to protect data across multiple jurisdictions.

  • Hackers leveraged compromised credentials from previous separate data breaches
  • 23andMe neglected to establish adequate authentication and verification measures
  • Approximately seven million users experienced exposure of genetic information on a global scale
  • Genetic data requires enhanced legal protections under current UK law

How hackers gained access to confidential data

The 2023 breach that exposed the DNA information of approximately 7 million 23andMe users was carried out through a comparatively uncomplicated yet highly damaging approach referred to as credential stuffing. Rather than implementing advanced attack techniques, attackers leveraged previously stolen credentials in earlier security incidents impacting other organisations and services. These compromised passwords were then routinely tried on 23andMe accounts, taking advantage of a widespread practice: the reuse of passwords among various digital platforms. This low-tech approach turned out to be strikingly efficient on 23andMe’s weak protective measures.

What made this attack particularly damaging was the confidential quality of the data being accessed. Genetic information serves as one of the most personal and permanent categories of data an person can own, exposing health vulnerabilities, family heritage, ethnicity, and information about blood relations. The breach was exacerbated when threat actors intentionally distributed the stolen data on the hidden networks, explicitly noting that it originated with Asian American Pacific Islander and Jewish users. This deliberate method prompted significant worry about potential discrimination and safety risks during a period defined by increasing hate crimes against these populations.

Password credential attacks explained

Credential stuffing is a cyber attack technique in which attackers rapidly feed substantial quantities of stolen login credentials to intended sites, wagering that people have recycled the identical login information across multiple platforms. This technique capitalises on typical user habits and inadequate password discipline rather than demanding sophisticated expertise. Once hackers break into into user accounts through credential stuffing, they may obtain the sensitive personal information held in. 23andMe’s inability to establish two-factor verification or alternative authentication methods made accounts susceptible to this fairly basic but extremely potent attack vector.

International regulatory measures and fines

The 2023 data breach has spurred significant regulatory scrutiny across various regions, with authorities worldwide taking action against 23andMe for its inability to sufficiently safeguard sensitive genetic information. The company has attracted considerable scrutiny for neglecting to establish fundamental protective safeguards such as two-factor verification and robust identity verification protocols. These oversights created critical vulnerabilities, allowing hackers to access numerous user records through fairly simple exploitation techniques. Regulators have emphasised that genetic data represents a special category of personal information necessitating stronger security measures under data protection laws, making 23andMe’s security failures particularly serious.

The UK’s Information Commissioner’s Office (ICO) imposed a penalty of £2.31 million on the organisation, following an investigation that uncovered 155,592 UK residents’ data was compromised during the breach. The ICO’s investigation, carried out jointly with Canada’s privacy commissioner, concluded that 23andMe had violated UK data protection law by failing to implement appropriate authentication and verification measures. The regulator’s conclusions highlighted widespread deficiencies in the company’s security architecture and its commitment to safeguarding customer privacy. Currently, California’s Attorney General has initiated proceedings against Chrome Holding, 23andMe’s successor company following the firm’s bankruptcy, claiming the predecessor company both failed to safeguard data but also misled consumers regarding how serious the breach was.

Jurisdiction Action taken
United Kingdom Information Commissioner’s Office fined 23andMe £2.31 million for failing to implement adequate security measures and protect 155,592 UK residents’ data
Canada Privacy Commissioner coordinated investigation with the UK ICO into 23andMe’s security failures and data protection violations
California, USA Attorney General Rob Bonta filed lawsuit against Chrome Holding, alleging predecessor 23andMe failed to protect customer data and misled consumers about breach severity

Extended implications concerning genetic data protection

The 23andMe breach followed by regulatory actions have uncovered core security gaps in how genetic information is safeguarded across the industry. Genetic data constitutes one of the most sensitive types of personal data, disclosing not only an individual’s health predispositions but also information regarding biological relatives and ancestry. The circumstance that stolen data was deliberately sold on the underground internet directed towards Asian American Pacific Islander and Jewish users introduces a deeply disturbing element, illustrating how genetic information can be used for targeted discrimination during periods of heightened social tension and hate crimes.

The case has raised urgent concerns about whether current data protection frameworks are adequately strong to handle the distinctive risks associated with genetic information. Companies working within this space must now contend with heightened expectations from regulators globally, who are increasingly treating genetic data as requiring special category protections. The California lawsuit constitutes a significant intensification in enforcement action, signalling that regulators will no longer tolerate inadequate security measures or false statements about data breaches. This shift is likely to reshape industry standards and force genetic testing companies to invest substantially in security infrastructure and disclosure standards.

  • Genetic data needs special legal protections due to its sensitive and irreversible nature
  • Credential stuffing attacks demonstrate the importance of multi-factor authentication and proper verification
  • Dark web sales targeted particular communities based on ethnicity and faith, raising worries about unfair treatment
  • International regulatory coordination strengthens action on major data protection violations
  • Companies must balance innovation with robust security and transparent breach communication

The company’s difficult journey to bankruptcy

23andMe’s slide into financial troubles constitutes a dramatic reversal of fortune for a firm that once commanded substantial investor backing and celebrity endorsement. At its height, the firm’s stock price climbed to $300, and it secured prominent clients such as Snoop Dogg, Oprah Winfrey, and Eva Longoria. The firm, cofounded by Anne Wojcicki—sibling of the former YouTube boss Susan Wojcicki and ex-wife of Google co-founder Sergey Brin—had established itself as a pioneering force in customised DNA testing. Yet, escalating operational problems and damage to its reputation from the 2023 data breach substantially eroded investor confidence and consumer trust.

The company’s bankruptcy filing last year marked a critical turning point, forcing it to divest operations through a court-supervised process. This shift created further difficulties for users, many of whom reported difficulties removing their profiles during the reorganisation phase. Concerns arose about potential data sales to insurers, with users worried that their genetic information could be applied to reject claims or inflate premiums. The later rebrand as Chrome Holding represented an effort to separate the company from its problematic history, yet the enforcement consequences from the breach has grown increasingly severe, with regulators globally taking legal measures that jeopardise the viability of the business model itself.