Rob Bonta sues 23andMe’s new owners over 2023 breach
California’s AG is suing 23andMe over its 2023 breach, alleging weak security and misleading public statements after the leak.
Intelligence analysis by GPT-5.4 Mini
The suit says 23andMe failed basic protections for sensitive DNA data, took months to spot the intrusion, and downplayed the breach while paying ransom. It now targets Chrome Holding Co. after TTAM Research Institute bought 23andMe’s assets.
23andMe is like a giant family photo album, except the photos are made from DNA. If one lock on the album is weak, a thief can peek at a lot of private family details.
California’s top lawyer says 23andMe did not protect that album well enough. He also says the company told people a softer story than what really happened after the break-in.
This matters because DNA is not like a normal password. If it leaks, a person cannot just change it. That is why the government is treating the case very seriously.
Analysis
What the suit says
California Attorney General Rob Bonta is suing 23andMe’s former corporate shell, Chrome Holding Co., over the company’s handling of the 2023 breach. The complaint says 23andMe did not use adequate security controls for highly sensitive records and then misled customers about what happened afterward.
Why the breach was so large
According to the article, the attacker known as Golem initially claimed to have data on millions of customers. Regulators later found the intruder directly breached about 14,000 accounts, but 23andMe’s DNA Relatives feature allowed access to information tied to nearly 7 million people. The article says the company did not detect the intrusion for five months, and the compromised accounts were hit through credential-stuffing attacks.
The legal and regulatory fallout
Bonta’s office says 23andMe’s statements to customers were misleading because the company downplayed the sensitivity of the stolen information, blamed users for reused passwords, and failed to disclose the full seriousness of the incident. The complaint also says the company was negotiating and paying a ransom at the same time it was publicly minimizing the breach.
The story lands after a series of penalties and settlements. The UK Information Commissioner fined 23andMe £2.3 million in June 2025, citing weak password requirements, slow detection, and poor controls against bulk downloading of genetic data. The company also settled a class action for $30 million in 2024. The broader issue for security teams is simple: highly sensitive data needs stronger default protections than ordinary consumer accounts, especially when one account can open paths to many others.
Key points
- California’s attorney general is suing 23andMe over the 2023 breach and its response.
- The complaint says the company used weak security for sensitive genetic data and misled customers afterward.
- A direct breach of about 14,000 accounts reportedly exposed information tied to nearly 7 million people through DNA Relatives.
- The article says 23andMe also paid a ransom while publicly downplaying the breach.
- The case follows prior fines and settlements, including a UK penalty and a $30 million class-action deal.



