California Sues 23andMe Over 2023 Data Breach That Affected 7 Million Users
California’s attorney general says 23andMe failed to protect genetic data in a 2023 breach that hit 7 million users.
Intelligence analysis by GPT-5.4 Mini

California Attorney General Rob Bonta is suing 23andMe, now Chrome Holding Co., over a breach that exposed sensitive genetic and health data from millions of users. The complaint says the company mishandled security, downplayed the risk, and left customers vulnerable for months.
23andMe is a company that keeps very private family and health information. California says some thieves got in by using stolen passwords, like opening a door with copied keys.
The state says the company did not guard the information well enough and did not tell people the full truth about what happened. It also says a part of the site helped the thieves see even more private details.
This matters because DNA information is not like a lost email password. It can reveal things about health, family, and where someone comes from, so a leak can follow a person for a long time.
Analysis
What California alleges
California Attorney General Rob Bonta says 23andMe failed to protect users’ sensitive personal information and genetic data, then misled customers about what was exposed. The lawsuit targets the company now known as Chrome Holding Co. and focuses on a 2023 breach that affected 7 million users across the U.S., including 855,541 Californians.
How the breach unfolded
According to the article, attackers used credential stuffing, a common method that relies on passwords stolen in earlier breaches. Bonta says 23andMe knew about the related MyHeritage breach but did not check for or prevent password reuse, even though it allegedly encouraged users to sign up for MyHeritage accounts. The hackers reportedly broke into 14,000 accounts first, then used a weakness in 23andMe’s DNA Relatives feature to reach more data.
The lawsuit says the company’s defenses were weak enough that the attackers stayed inside the system for five months without being detected. Bonta says 23andMe only began investigating after stolen data was already being sold on the dark web and ransom demands had started.
Why regulators care
Bonta also accuses the company of omitting key details when notifying customers. He says 23andMe downplayed how sensitive the stolen data was and described the DNA Relatives feature as “essentially public,” while privately negotiating with the attackers. The article says the stolen dataset included information about Asian American and Pacific Islanders and Jewish users, which Bonta called “disturbing and incredibly dangerous.”
23andMe filed for bankruptcy in March 2025. The article also notes a class-action case and a judge-approved $50 million settlement earlier this year.
Key points
- California’s attorney general sued 23andMe over a 2023 breach that affected 7 million users.
- The lawsuit says attackers used credential stuffing and then exploited a weakness in the DNA Relatives feature.
- Bonta alleges the company failed to stop password reuse and left the attack undetected for five months.
- The complaint says 23andMe downplayed the sensitivity of the stolen data in its breach notice.
- 23andMe filed for bankruptcy in March 2025 and had already faced a separate class-action case.



