23andMe Sued by California Over Massive 2023 Data Breach
California sued 23andMe’s parent company, saying weak security let hackers steal sensitive data from nearly 7 million people in 2023.
Intelligence analysis by GPT-5.4 Mini
California’s attorney general says 23andMe ignored warning signs and failed to protect customer data during a breach that exposed ancestry and genetic information. The case adds legal pressure after earlier lawsuits and a bankruptcy-era ownership change.
23andMe was a company that let people learn about their family roots and DNA by mailing in a sample. But hackers got into its systems and took private information from millions of people.
California says the company did not guard the data well enough and did not react fast enough when warning signs appeared. It is like leaving a house key under the mat and then not checking the door even after someone says they saw it open.
The case matters because DNA data is very personal. If that kind of information leaks, it can affect people for a long time, even after the company changes hands.
Analysis
What California alleges
California Attorney General Rob Bonta sued Chrome Holding Co., the company formerly known as 23andMe, in San Francisco Superior Court. The complaint says the company did not adequately protect customer information and failed to properly investigate or respond to repeated warnings that its systems had been compromised.
The breach dates back to 2023, when attackers used a credential-stuffing attack, meaning they tried large numbers of stolen username-and-password combinations from other breaches. According to the article, the intruders stayed in 23andMe’s systems for more than five months and eventually accessed ancestry and genetic data tied to nearly 7 million people.
Why the case is serious
Bonta’s office says the company’s security was so weak that the threat actor operated undetected for months. The complaint also says 23andMe only started investigating after the attacker offered stolen user data for sale on the dark web and contacted the company to demand ransom.
The article says the breach especially affected people with Chinese or Ashkenazi Jewish ancestry. It also notes that more than 1 million Asian-Pacific Islander and Ashkenazi Jewish users had stolen data posted for sale online. Bonta described that timing as especially disturbing because it happened during a period of rising anti-Asian American Pacific Islander and antisemitic hate and violence.
The wider fallout
This is not the first lawsuit over the breach. A January 2024 case said 23andMe did not do enough to protect customers and failed to notify some people whose data had been specifically targeted. That case later settled for $30 million.
The company’s fortunes have also changed sharply. After going public in 2021, its momentum faded, it filed for bankruptcy in 2025, and TTAM Research Institute, a nonprofit led by cofounder Anne Wojcicki, bought its assets for $305 million last July.
Key points
- California’s attorney general sued 23andMe’s parent company over the 2023 breach.
- The complaint says hackers used credential stuffing and stayed inside the systems for months.
- Nearly 7 million people were exposed, including sensitive ancestry and genetic data.
- The lawsuit says the company ignored warning signs and only investigated after the stolen data appeared on the dark web.
- The breach has already led to earlier litigation and a $30 million settlement.



