California AG sues 23andMe over 2023 breach exposing health data
California's attorney general sued 23andMe, saying weak defenses and misleading claims helped expose genetic and health data from millions in a 2023 breach.
Intelligence analysis by GPT-5.4 Mini
California Attorney General Rob Bonta says 23andMe failed to block credential-stuffing attacks, missed chances to spot the intrusion, and overlooked a coding flaw that widened the breach. The lawsuit also says the company downplayed the incident and made misleading public claims about its security.
23andMe kept a huge file cabinet of people’s DNA and health details. The article says hackers found a weak spot and copied records from millions of people, including many in California.
The California attorney general says the company did not lock the cabinet well enough, did not notice the break-in fast enough, and then said things that made the problem sound smaller than it was.
It is like leaving a house with a weak door lock, then telling neighbors the door was fine after a thief came in. The lawsuit asks a judge to force better safety and punish the company for each mistake.
Analysis
What happened
California Attorney General Rob Bonta has sued 23andMe, now Chrome Holding Co., over the company’s handling of the 2023 breach that exposed sensitive customer information. The article says the incident affected nearly 7 million people overall, including 855,541 Californians, and involved genetic data, health predisposition details, ancestry and ethnicity information, biological relatives, and DNA matches.
Why the state is suing
According to the complaint, 23andMe did not put in place reasonable protections against credential-stuffing attacks, failed to notice signs of intrusion in time, and missed a coding error in the DNA Relatives feature that helped widen the damage. The lawsuit also says the company made misleading statements before and after the breach. Before the incident, it said its security met high standards. Afterward, it reportedly downplayed the exposure, suggested the leaked information was mostly public, and blamed users for password reuse while saying its systems had not been breached.
Legal stakes
Bonta says those actions violated several California laws, including the California Genetic Information Privacy Act, the California Reasonable Data Security Law, the California Consumer Privacy Act, the False Advertising Law, and the Unfair Competition Law. The complaint seeks an injunction to stop further violations and asks for statutory penalties ranging from $1,000 to $7,500 per violation, depending on the case. The article also notes that the bankruptcy dispute over a proposed sale of Californians’ genetic data and biological materials is a separate proceeding.
Key points
- California's attorney general sued 23andMe over the 2023 breach and its handling of the fallout.
- The lawsuit says weak protections, missed detection opportunities, and a coding error helped expose sensitive data.
- The breach affected nearly 7 million people, including 855,541 Californians.
- The complaint says 23andMe made misleading security claims before and after the incident.
- The state seeks an injunction and statutory penalties under multiple California laws.



