California has sued 23andMe, now operating as Chrome Holding Co., alleging the company failed to adequately protect customers’ genetic and account data in the 2023 breach affecting nearly 7 million people. The complaint says attackers used credential stuffing—trying usernames and passwords stolen elsewhere—to access about 14,000 accounts, then scrape broader data through 23andMe’s DNA Relatives features; the state also alleges 23andMe failed to require stronger safeguards such as multifactor authentication, missed warning signs for months, and only acted after stolen data was advertised for sale and ransom demands were made.
2026.07.21
93% relevant
This updates the same underlying 2023 23andMe breach by adding Spain’s €2.4 million GDPR fine, findings that missing mandatory MFA and lack of rate limits enabled the credential-stuffing attack, and that the company notified Spanish authorities 12 days after learning of the breach.
Sergiu Gatlan
2026.07.16
95% relevant
This article is a direct follow-up to the same 2023 23andMe breach, adding that 23andMe agreed to an $18 million settlement with 43 attorneys general, plus new details on investigators’ findings about missing MFA, rate limiting, monitoring, and breach response failures.
2026.07.15
94% relevant
This article updates the same underlying 2023 23andMe breach by reporting a new multistate $18 million settlement, specific attorney-general findings about missing credential-abuse defenses, logging, monitoring, and vulnerability remediation, plus ongoing requirements tied to customer deletion rights and the successor research institute that now holds the data.
2026.06.12
88% relevant
This article updates the same underlying 23andMe 2023 breach by reporting that a bankruptcy administrator approved a $46.8 million settlement fund for victims, including payout structure details and the company's bankruptcy context.
Bill Toulas
2026.05.29
98% relevant
This is the same underlying event: California's lawsuit over the 2023 23andMe breach. The article adds details on the complaint's allegations, including failure to defend against credential stuffing, missed intrusion-detection opportunities, a DNA Relatives coding error, and claims that 23andMe misled users before and after the breach.
2026.05.29
98% relevant
This article is the same underlying event: California's lawsuit over 23andMe's 2023 breach. It adds that the suit is now directed at Chrome Holding Co., the post-sale successor to 23andMe, and emphasizes allegations that the company downplayed the breach, failed to implement basic safeguards such as stronger MFA adoption, detected the intrusion only after months, and paid a ransom to the attacker.
Associated Press
2026.05.29
100% relevant
This article establishes a trackable new story because it is not just a recap of the 2023 23andMe breach; it is a concrete state legal action alleging specific security failures, privacy-law violations, and mishandling of genetic data tied to that breach.