Substrate
technology

California AG Sues 23andMe Successor Chrome Holding Over 2023 Data Breach Affecting 7 Million Users

Rob Bonta filed suit Thursday in San Francisco Superior Court against the company formerly known as 23andMe, alleging it failed to protect customer data and misled users about the breach.

FO
BBC News
Los Angeles Times
3 sources·May 28, 2:28 PM·2m read
California AG Sues 23andMe Successor Chrome Holding Over 2023 Data Breach Affecting 7 Million Usersnewser.com
Audio version
Tap play to generate a narrated version.

The corporate debtor name used by 23andMe during its bankruptcy, alleging the company failed to protect sensitive genetic data in a 2023 breach that affected nearly 7 million people nationwide, including more than 850,000 Californians. The complaint, filed in San Francisco Superior Court, states that hackers accessed approximately 14,000 accounts through credential stuffing and obtained raw genetic data, health reports, DNA shared with relatives, locations and birth years of relatives, ancestry, ethnicity, and genetic predispositions and risk factors.

The breach exposed personal information belonging to Asian-Pacific Islander and Ashkenazi Jewish users that later appeared for sale on the dark web.

Bonta said the company failed to take basic steps to protect users' data. “23andMe collected genetic data about millions of people, failed to meet its obligation under California law to keep that information safe, and then lied to consumers about the severity of its 2023 data breach,” he stated.

The lawsuit alleges that 23andMe did not require customers to reset passwords or implement multifactor authentication after a 2017 MyHeritage breach that exposed credentials later used in the attack.

A suspicious spike in login attempts occurred in July 2023 and a Reddit post discussed a possible breach in August 2023, yet the company only began investigating after the data was offered for sale and a ransom was demanded. The threat actor operated undetected within 23andMe’s systems for over five months, according to the California Department of Justice investigation cited in the complaint.

After notifying the public in October 2023, the company continued to mislead consumers about the breach’s severity and its own role, the lawsuit states.

Chrome Holding Co. is a subsidiary of TTAM Research Institute, the nonprofit led by former 23andMe CEO Anne Wojcicki that acquired the company after its March 2025 bankruptcy filing. Bonta had intervened in the Chapter 11 proceedings to ensure genetic data would not be mishandled, citing California’s Genetic Information Privacy Act, which requires opt-in consent before selling such information to third parties.

The bankruptcy sale was allowed to proceed. 23andMe was founded in San Francisco in 2006 and had collected around 15 million DNA samples by the time of its bankruptcy filing. In 2024 the company agreed to a $30 million class-action settlement over the breach; the amount was later raised to $50 million and received final approval in January from a federal judge overseeing the bankruptcy.

31 million last year after finding that personal data of 155,592 UK residents was accessed. The ICO investigation, conducted in coordination with Canada’s privacy commissioner, determined that 23andMe violated UK law by failing to implement appropriate authentication measures.

Bonta said the sale of the data on the dark web was “disturbing and incredibly dangerous” given it occurred during a period of mounting anti-Asian American and Pacific Islander and antisemitic hate and violence.

The lawsuit seeks civil penalties and injunctions to block further violations of California privacy laws.

Transparency

How sources framed this
FOBBC NewsLos Angeles Times
LeftNeutralRightNegligenceSophisticated at

Story details

Related Stories

Alphabet to Sell $80 Billion in Stock, Including $10B to Berkshire Hathaway, to Fund AI Infrastructure PushFrance 24
technology1 hr ago

Alphabet to Sell $80 Billion in Stock, Including $10B to Berkshire Hathaway, to Fund AI Infrastructure Push

Alphabet announced a stock sale of $80 billion, including a $10 billion placement to Berkshire Hathaway. Proceeds will fund capital expenditures to scale AI infrastructure.

TechCrunch
cnbc.com
thestockmarketwatch.com
livemint.com
Financial Times
+1
6 sources
Anthropic Confidentially Files for IPO After Raising $65 Billionjapantoday.com
ai11 hrs agoFraming65Framing risk65/100Rewrite inherits heavy consensus framing from sources, using loaded metaphors, anonymous speculation on market disruption, and lede misdirection that buries the substantive $65B raise and near-$1T valuation behind IPO process and competitivClick to jump to full framing analysis

Anthropic Confidentially Files for IPO After Raising $65 Billion

The artificial intelligence company behind the Claude chatbot submitted its filing on Monday, weeks after completing a funding round that more than doubled its valuation from February. Anthropic did not disclose the size or terms of the offering. The move comes as the global IPO…

Cbc
nypost.com
The Guardian
Financial Times
Cnn
5 sources
Instagram patches vulnerability allowing account hijacks through Meta AI chatbotthenextweb.com
ai1 hr agoFraming55Framing risk55/100The rewrite is largely neutral and fact-focused, with only mild inherited valence in phrasing around the hack and limited sourcing.Click to jump to full framing analysis

Instagram patches vulnerability allowing account hijacks through Meta AI chatbot

Instagram restored access after hackers used its AI support chatbot to add new emails and reset passwords on multiple accounts. The company confirmed the issue was resolved Monday.

Techcrunch
Ars Technica
thenextweb.com
itsecuritynews.info
4 sources