Substrate
technology

California Attorney General Sues 23andMe Over 2023 Data Breach

California’s attorney general filed suit against the genetic testing company, alleging inadequate security allowed a 2023 breach that exposed data of nearly 7 million users. The complaint seeks civil penalties and orders barring further violations of state privacy law.

Fortune
1 source·May 29, 1:30 PM(3 hrs ago)·2m read
California Attorney General Sues 23andMe Over 2023 Data Breachfoxnews.com
Audio version
Tap play to generate a narrated version.

California’s attorney general sued the genetic testing company formerly known as 23andMe on Thursday, alleging it failed to protect sensitive user data in a 2023 breach that affected nearly 7 million people across the country. , which 23andMe rebranded under after filing for bankruptcy last March.

The company is known for its direct-to-consumer DNA test kits that provided customers information on their ancestry and genetic predispositions for certain health conditions. The lawsuit calls for various civil penalties against the company and injunctions blocking further violations of California’s privacy protection laws.

Prosecutors said the company’s security measures were so lax that the threat actor operated undetected within its systems for over five months.

The company has acknowledged that it suffered a major security breach in 2023 that resulted in about 14,000 accounts accessed, through which attackers stole the data of nearly 7 million customers. The cyberattack utilized credential stuffing, which takes advantage of customers’ tendency to use weak or common passwords or reuse passwords between multiple accounts.

Bonta’s office said this was a well-known attack that businesses should know to guard against. The attackers used stolen user account credentials including ones from a massive data breach in October 2017 that affected MyHeritage, one of the company’s former partners.

After that breach, the company did not take common protocols such as asking customers to reset their passwords or use multifactor authentication. The company did not immediately respond to an emailed request for comment. Prosecutors said the company only began investigating after the threat actor offered the stolen user data for sale on the dark web and reached out to demand a ransom.

October 2023, the stolen data appeared for sale on the dark web, with the poster specifically touting that about 1.1 million consumers’ data belonged to Asian-Pacific Islander and Ashkenazi Jewish users. Some of the data stolen included raw genetic data, health reports, DNA shared with other relatives, and locations and birth years of relatives.

The lawsuit says that after notifying the public about the breach, the company continued to mislead consumers about the severity of the breach and the company’s role in it. The company has said it only found out about the breach in October 2023 when the stolen data was posted for sale on the dark web.

The lawsuit said the company failed to properly investigate red flags that appeared months earlier, such as a suspicious spike in user login attempts in July and a post discussing a possible breach and sale of user data in August. Genetic data requires one of the highest levels of protection and California law mandates a heightened legal obligation to protect it, the lawsuit said.

In 2024, the company agreed to pay a $30 million settlement in a class-action lawsuit accusing it of failing to protect customers whose personal information was exposed in the breach. The amount was raised to $50 million to resolve most U.S. customer claims and received final approval in January by a federal judge overseeing the company’s bankruptcy.

Key Facts

Nearly 7 million users
affected by 2023 data breach at genetic testing firm
$50 million settlement
class-action payout approved in January for U.S. customers
Over five months
attacker operated undetected inside company systems
Chrome Holding Co.
current corporate name after 23andMe bankruptcy rebrand

Story Timeline

5 events
  1. October 2017

    Massive data breach affected MyHeritage, a former 23andMe partner.

    1 sourceFortune
  2. 2023

    Credential-stuffing attack accessed 14,000 accounts and exposed data of nearly 7 million customers.

    1 sourceFortune
  3. October 2023

    Stolen data appeared for sale on the dark web; company said it first learned of breach.

    1 sourceFortune
  4. January 2026

    Federal judge gave final approval to $50 million class-action settlement.

    1 sourceFortune
  5. Thursday

    California attorney general filed lawsuit against Chrome Holding Co. over the breach.

    1 sourceFortune

Potential Impact

  1. 01

    Company faces additional civil penalties if court finds privacy-law violations.

  2. 02

    Further restrictions on handling of genetic data could be ordered by the court.

  3. 03

    Bankruptcy asset sale already completed; ruling would not unwind prior transaction.

Transparency Panel

Sources cross-referenced1
Confidence score75%
Synthesized bySubstrate AI
Word count519 words
PublishedMay 29, 2026, 1:30 PM
Bias signals removed1 across 1 outlet
Signal Breakdown
Editorializing 1

Related Stories

World Urban Forum 2026 Draws 57,000 Participants from 176 CountriesEuronews
technology3 hrs agoDeveloping

World Urban Forum 2026 Draws 57,000 Participants from 176 Countries

The 13th World Urban Forum concluded with discussions on housing, climate resilience and urban governance. Organisers reported that the sessions informed future strategic priorities.

Euronews
1 source
Trump Mobile website still lists T1 phone as American-madetheverge.com
technology3 hrs agoDeveloping

Trump Mobile website still lists T1 phone as American-made

The product page for the T1 phone continues to describe the device as American-made. The Verge reported that the site may conflict with FTC advertising rules. The phone was announced in June 2025.

The Verge
1 source
EU Discusses Readiness for Artificial Intelligence ChangesFrance 24
ai3 hrs agoDeveloping

EU Discusses Readiness for Artificial Intelligence Changes

A France 24 program examined whether European Union policies can address the effects of artificial intelligence. The discussion covered potential impacts across daily life and economic sectors.

France 24
1 source