California sues 23andMe over the 2023 breach that exposed genetic and profile data of nearly 7 million people

California has sued 23andMe, now operating as Chrome Holding Co., alleging the company failed to adequately protect customers’ genetic and account data in the 2023 breach affecting nearly 7 million people. The complaint says attackers used credential stuffing—trying usernames and passwords stolen elsewhere—to access about 14,000 accounts, then scrape broader data through 23andMe’s DNA Relatives features; the state also alleges 23andMe failed to require stronger safeguards such as multifactor authentication, missed warning signs for months, and only acted after stolen data was advertised for sale and ransom demands were made.
Why it matters: This matters because the stolen information included highly sensitive genetic and health-related data, and the lawsuit may shape how companies are expected to protect and handle biometric and genomic records. Affected users should reset reused passwords, enable multifactor authentication where available, and review what personal and relative-sharing data remains in their account.

Sources

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
2026.07.21 93% relevant
This updates the same underlying 2023 23andMe breach by adding Spain’s €2.4 million GDPR fine, findings that missing mandatory MFA and lack of rate limits enabled the credential-stuffing attack, and that the company notified Spanish authorities 12 days after learning of the breach.
23andMe to pay $18 million in new genetics data breach settlement
Sergiu Gatlan 2026.07.16 95% relevant
This article is a direct follow-up to the same 2023 23andMe breach, adding that 23andMe agreed to an $18 million settlement with 43 attorneys general, plus new details on investigators’ findings about missing MFA, rate limiting, monitoring, and breach response failures.
23andMe reaches $18 million settlement with states for massive breach
2026.07.15 94% relevant
This article updates the same underlying 2023 23andMe breach by reporting a new multistate $18 million settlement, specific attorney-general findings about missing credential-abuse defenses, logging, monitoring, and vulnerability remediation, plus ongoing requirements tied to customer deletion rights and the successor research institute that now holds the data.
Bankruptcy admin approves settlement fund of $47 million for 23andMe data breach victims
2026.06.12 88% relevant
This article updates the same underlying 23andMe 2023 breach by reporting that a bankruptcy administrator approved a $46.8 million settlement fund for victims, including payout structure details and the company's bankruptcy context.
California AG sues 23andMe over 2023 breach exposing health data
Bill Toulas 2026.05.29 98% relevant
This is the same underlying event: California's lawsuit over the 2023 23andMe breach. The article adds details on the complaint's allegations, including failure to defend against credential stuffing, missed intrusion-detection opportunities, a DNA Relatives coding error, and claims that 23andMe misled users before and after the breach.
23andMe inherits lawsuit over 'disturbing' DNA data breach
2026.05.29 98% relevant
This article is the same underlying event: California's lawsuit over 23andMe's 2023 breach. It adds that the suit is now directed at Chrome Holding Co., the post-sale successor to 23andMe, and emphasizes allegations that the company downplayed the breach, failed to implement basic safeguards such as stronger MFA adoption, detected the intrusion only after months, and paid a ransom to the attacker.
California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach
Associated Press 2026.05.29 100% relevant
This article establishes a trackable new story because it is not just a recap of the 2023 23andMe breach; it is a concrete state legal action alleging specific security failures, privacy-law violations, and mishandling of genetic data tied to that breach.
← Back to all stories