California Attorney General sues 23andMe successor for 2023 data breach
California's attorney general says 23andMe's successor failed to protect customer data in a 2023 breach that exposed genetic and ancestry details.
Intelligence analysis by GPT-5.4 Mini
Rob Bonta plans to sue Chrome Holding, the rebranded 23andMe, over a breach he says exposed sensitive DNA data for nearly seven million users. The case adds fresh pressure on a company already facing global privacy scrutiny.
A company that stores family DNA is like a locked box full of private family secrets. The article says hackers got in by using old passwords that still worked on some accounts.
California’s top lawyer says the company did not protect that box well enough. The information was not just a name and email; it was deep personal stuff about family, health, and where people come from.
Now the state wants to take the company to court. The fight matters because if DNA data leaks, it can affect one person and their relatives too, like a spilled ink bottle staining many pages in the same family book.
Analysis
What California alleges
California Attorney General Rob Bonta says he will sue Chrome Holding, the company that emerged after 23andMe filed for bankruptcy, over a 2023 breach that exposed highly sensitive customer information. According to the article, the affected data included genetic predispositions, risk factors, ancestry, ethnicity, and information about biological relatives for nearly seven million users.
Bonta says the company failed to take basic steps to protect user data and also misled consumers about how serious the breach was. The article says the attack involved credential stuffing, where hackers reused passwords exposed in earlier breaches to enter accounts that used similar logins.
Wider regulatory pressure
The California case follows other privacy action abroad. The article says the UK Information Commissioner's Office fined 23andMe £2.31 million last year after finding that personal data of 155,592 UK residents was accessed and that the company had not put adequate protections in place. The ICO’s probe was coordinated with Canada’s privacy commissioner.
The article also says threat actors later sold 23andMe user data on the dark web and highlighted that some records belonged to Asian American Pacific Islanders and Jewish users. Bonta said that made the incident especially dangerous given the wider climate of anti-Asian and antisemitic hate.
Business context
23andMe, once a high-flying consumer genetics company, has since rebranded and changed hands after bankruptcy. The lawsuit suggests its privacy problems are not just a technical issue but a continuing business and regulatory liability tied to how it handled some of the most personal data people can share.
Key points
- California Attorney General Rob Bonta says he will sue Chrome Holding, the company formed after 23andMe's bankruptcy.
- The alleged 2023 breach exposed genetic and ancestry data for nearly seven million users, according to the article.
- Bonta says the company failed to protect customer data and downplayed the seriousness of the breach.
- The article says the attack used credential stuffing, where stolen passwords from earlier breaches were reused.
- 23andMe has already faced UK regulatory fines and broader scrutiny over how it handled sensitive genetic data.



