# California Sues 23andMe Over Massive 2023 Genetic Data Breach: State Claims Company Failed Basic Security Protections
California's Attorney General alleges that 23andMe failed to implement basic cybersecurity measures, leaving millions of users' sensitive genetic and health information exposed to unauthorized access.
---
## The Lawsuit: California's Case Against 23andMe
California Attorney General Rob Bonta has filed a formal lawsuit against Chrome Holding Co., the entity through which 23andMe rebranded following its bankruptcy filing in March 2024. The legal action centers on allegations that the genetic testing company failed to protect user data during a significant 2023 data breach that exposed sensitive personal information for millions of customers.
The lawsuit represents a major enforcement action against one of the world's largest direct-to-consumer genetic testing platforms, signaling heightened regulatory scrutiny of how biotech and genetic companies handle consumer privacy. California's action follows similar investigations and enforcement efforts across multiple state attorneys general offices investigating the company's security practices.
---
## Background: The 2023 Breach and Its Scope
The breach in question occurred in 2023, though details about the full scope emerged gradually through 2024. The incident resulted in unauthorized access to genetic information, ancestry data, and associated health information for a substantial portion of 23andMe's user base. While the company initially downplayed the severity, subsequent reporting revealed that the exposure was far more extensive than initially acknowledged.
Timeline of Events:
The breach reportedly affected millions of customers who had created accounts on the 23andMe platform. Sensitive data exposed included:
---
## The Security Failures Alleged
California's complaint centers on what the state characterizes as grossly inadequate cybersecurity protections that fell well below industry standards. The Attorney General's office alleges that 23andMe:
Failed to Implement Basic Protective Measures:
Inadequate Response and Notification:
Systemic Security Deficiencies:
The allegations suggest that 23andMe treated genetic data—among the most sensitive information a company can hold—with security practices that would be considered substandard even for less sensitive data types.
---
## Why This Case Matters: Genetic Data Privacy at Stake
This lawsuit carries implications that extend far beyond a single company. Genetic data represents a unique category of personal information: it is permanent, inheritable, and carries implications not just for the individual tested but for blood relatives who share the same DNA. Unlike passwords or credit card numbers, genetic information cannot be changed if compromised.
The lawsuit underscores a critical vulnerability in the biotech industry's approach to consumer privacy. While 23andMe has marketed itself as a trusted custodian of genetic information, the breach and subsequent company restructuring raise questions about whether direct-to-consumer genetic testing companies have adequate incentives to prioritize security over growth and profitability.
Broader Industry Implications:
---
## The Corporate Restructuring Question
A notable element of this case is that the lawsuit targets Chrome Holding Co., the entity through which 23andMe has reorganized. In March 2024, 23andMe filed for bankruptcy protection following significant stock price decline and declining consumer confidence post-breach. The company subsequently emerged under a new corporate structure.
California's decision to pursue the rebranded entity suggests that state regulators will not permit companies to escape accountability through corporate restructuring. This has important implications: companies cannot simply rebrand or reorganize to shed liability for past security failures and regulatory violations.
---
## What This Means for Users and the Industry
For 23andMe Users:
Millions of customers who submitted genetic samples to 23andMe now face an uncertain landscape. Their genetic information remains exposed through breaches, and the company's financial instability creates ongoing questions about long-term data stewardship and storage practices. Users affected by the breach should consider identity theft protection, genetic privacy monitoring services, and consulting with legal counsel about participation in class action settlements.
For the Genetic Testing Industry:
This lawsuit signals that regulators expect genetic testing companies to implement enterprise-grade security for consumer data. Other direct-to-consumer genetic testing providers—including MyHeritage, Ancestry, and others—should anticipate similar regulatory scrutiny and may face pressure to publicly demonstrate enhanced security practices.
For Healthcare and Biotech Companies:
The enforcement action reinforces that regulators and courts will hold companies accountable when they fail to protect sensitive health data, regardless of corporate structure or profitability.
---
## Legal and Regulatory Implications
The lawsuit leverages California's strong data privacy laws, including provisions of the California Consumer Privacy Act (CCPA) and California's broader consumer protection statutes. If successful, the state could seek:
This case is also watched closely by privacy advocates and regulators nationwide as a test of whether states can effectively enforce accountability against technology companies that mishandle sensitive personal data.
---
## HackWire Analysis
The California lawsuit against 23andMe represents a critical inflection point in how regulators approach genetic data privacy and corporate accountability. What's significant here is not merely that a breach occurred—security incidents happen in every industry—but rather that a major company treated exceptionally sensitive genetic information with security controls that would be considered inadequate even for routine customer databases.
The timing of this enforcement action is particularly important. The lawsuit suggests that California regulators have concluded their investigation and determined that 23andMe's failures were not merely technical or accidental, but systemic and preventable. The company's pivot to bankruptcy restructuring and rebranding appears to have hardened, rather than softened, regulatory resolve. Courts and regulators are signaling that corporate reorganization is not a liability shield.
There is also a pattern recognition element: 23andMe is not the first high-profile company to suffer a major breach and subsequently attempt to minimize accountability. The difference here is that California has moved beyond pressure campaigns and class actions to formal enforcement. This establishes a higher bar for genetic testing and biotech companies.
The hidden risk in this story is what happens if 23andMe (now Chrome Holding Co.) lacks resources to fund both remediation obligations *and* ongoing operations. Bankruptcy protections and corporate restructuring may have reduced the company's capital position, creating a scenario where regulatory penalties cannot be fully satisfied or where customer refunds for data compromises become impossible. This highlights a critical gap: there may be insufficient mechanisms to ensure that companies harmed by security failures can actually be made whole.
For defenders in the genetic testing and healthcare biotech space, the implication is clear: genetic data demands genetic-grade security, not standard baseline protections. Organizations handling genetic information should conduct third-party security audits, implement mandatory multi-factor authentication, encrypt all data at rest and in transit, and maintain comprehensive audit logs of all data access. — HackWire Editorial
---
## Recommendations for Organizations and Individuals
For Organizations Handling Genetic Data:
For Consumers:
---
## Related Coverage