Unbiased AI-powered news
Rob Bonta filed suit Thursday in San Francisco Superior Court against the company formerly known as 23andMe, alleging it failed to protect customer data and misled users about the breach.
newser.comCalifornia Attorney General Rob Bonta sued Chrome Holding Co., the successor company to 23andMe, in San Francisco Superior Court on Thursday, alleging violations of the California Consumer Privacy Act and the Genetic Information Privacy Act in connection with a 2023 data breach.
According to the complaint, hackers used credential stuffing to access approximately 14,000 accounts and obtained raw genetic data, health reports, DNA shared with relatives, locations and birth years of relatives, ancestry, ethnicity, and genetic predispositions and risk factors.
The breach affected nearly 7 million people nationwide, including more than 850,000 Californians. Personal information belonging to users of Ashkenazi Jewish and Asian-Pacific Islander descent later appeared for sale on the dark web.
The complaint states that a suspicious spike in login attempts occurred in July 2023. A Reddit post discussed a possible breach in August 2023. The company began investigating after the data was offered for sale and a ransom was demanded, according to the California Department of Justice investigation cited in the filing.
The threat actor operated undetected within 23andMe’s systems for over five months.
” The lawsuit alleges the company did not require customers to reset passwords or implement multifactor authentication after a 2017 MyHeritage breach that exposed credentials later used in the attack.
Chrome Holding Co. is a subsidiary of TTAM Research Institute, the nonprofit led by former 23andMe CEO Anne Wojcicki that acquired the company following its March 2025 Chapter 11 bankruptcy filing. Bonta had intervened in the bankruptcy proceedings to ensure genetic data would not be mishandled, citing the Genetic Information Privacy Act’s requirement for opt-in consent before selling such information to third parties.
The bankruptcy sale was allowed to proceed.
23andMe was founded in San Francisco in 2006 and had collected around 15 million DNA samples by the time of its bankruptcy filing. In 2024 the company agreed to a class-action settlement over the breach; the amount was raised to $50 million and received final approval in January from a federal judge overseeing the bankruptcy.
The UK Information Commissioner’s Office fined 23andMe £2.31 million last year after finding that personal data of 155,592 UK residents was accessed. The ICO investigation, conducted in coordination with Canada’s privacy commissioner, determined that 23andMe violated UK law by failing to implement appropriate authentication measures.
Bonta said the sale of the data on the dark web was “disturbing and incredibly dangerous” given it occurred during a period of mounting anti-Asian American and Pacific Islander and antisemitic hate and violence. The lawsuit seeks civil penalties and injunctions to block further violations of California privacy laws.
androidpolice.comThe models add specialized cybersecurity capabilities and lower-cost options to the Gemini lineup. They target efficiency gains in coding, high-volume tasks, and vulnerability detection.
america.cgtn.comTreasury Secretary Scott Bessent said Tuesday the United States would check Chinese open-source AI models for signs of intellectual property theft and could impose sanctions if theft is found. The remarks follow recent advances by models such as Moonshot AI’s Kimi K3.
theverge.comApple plans to introduce a device leasing option through a financing partner to encourage more frequent upgrades. The program aims to address slowing iPhone sales by making newer devices more accessible to customers.