# California Sues 23andMe Over Massive 2023 Genetic Data Breach: State Claims Company Failed Basic Security Protections


California's Attorney General alleges that 23andMe failed to implement basic cybersecurity measures, leaving millions of users' sensitive genetic and health information exposed to unauthorized access.


---


## The Lawsuit: California's Case Against 23andMe


California Attorney General Rob Bonta has filed a formal lawsuit against Chrome Holding Co., the entity through which 23andMe rebranded following its bankruptcy filing in March 2024. The legal action centers on allegations that the genetic testing company failed to protect user data during a significant 2023 data breach that exposed sensitive personal information for millions of customers.


The lawsuit represents a major enforcement action against one of the world's largest direct-to-consumer genetic testing platforms, signaling heightened regulatory scrutiny of how biotech and genetic companies handle consumer privacy. California's action follows similar investigations and enforcement efforts across multiple state attorneys general offices investigating the company's security practices.


---


## Background: The 2023 Breach and Its Scope


The breach in question occurred in 2023, though details about the full scope emerged gradually through 2024. The incident resulted in unauthorized access to genetic information, ancestry data, and associated health information for a substantial portion of 23andMe's user base. While the company initially downplayed the severity, subsequent reporting revealed that the exposure was far more extensive than initially acknowledged.


Timeline of Events:

  • 2023: Breach occurs; unauthorized access to user databases confirmed
  • Late 2023: 23andMe initially notifies affected users
  • Early 2024: Full scope of the breach becomes public; user class action lawsuits begin
  • March 2024: 23andMe files for bankruptcy protection
  • May 2024: 23andMe rebrands as Chrome Holding Co. (renamed subsidiary structure)
  • 2024-2025: California Attorney General investigation concludes; lawsuit filed

  • The breach reportedly affected millions of customers who had created accounts on the 23andMe platform. Sensitive data exposed included:

  • DNA and genetic profile information
  • Ancestry composition reports
  • Health predisposition data
  • Personal identification information
  • Associated health records and medical histories

  • ---


    ## The Security Failures Alleged


    California's complaint centers on what the state characterizes as grossly inadequate cybersecurity protections that fell well below industry standards. The Attorney General's office alleges that 23andMe:


    Failed to Implement Basic Protective Measures:

  • Lacked proper encryption standards for sensitive genetic data
  • Maintained insufficient access controls on databases containing personal genetic information
  • Failed to deploy multi-factor authentication (MFA) across accounts as a security baseline
  • Did not implement rate-limiting or anomaly detection systems that could have identified unauthorized access attempts

  • Inadequate Response and Notification:

  • Delayed notifying users of the breach and the full extent of exposure
  • Provided insufficient guidance to affected users about remediation steps
  • Failed to adequately assess the scope and impact of the breach before public disclosure

  • Systemic Security Deficiencies:

  • No evidence of regular security audits or penetration testing
  • Inadequate data governance and retention policies
  • Insufficient employee training on data security protocols
  • Lack of comprehensive incident response procedures

  • The allegations suggest that 23andMe treated genetic data—among the most sensitive information a company can hold—with security practices that would be considered substandard even for less sensitive data types.


    ---


    ## Why This Case Matters: Genetic Data Privacy at Stake


    This lawsuit carries implications that extend far beyond a single company. Genetic data represents a unique category of personal information: it is permanent, inheritable, and carries implications not just for the individual tested but for blood relatives who share the same DNA. Unlike passwords or credit card numbers, genetic information cannot be changed if compromised.


    The lawsuit underscores a critical vulnerability in the biotech industry's approach to consumer privacy. While 23andMe has marketed itself as a trusted custodian of genetic information, the breach and subsequent company restructuring raise questions about whether direct-to-consumer genetic testing companies have adequate incentives to prioritize security over growth and profitability.


    Broader Industry Implications:

  • Establishes state-level enforcement expectations for genetic data handling
  • Creates precedent for holding biotech companies liable for security failures
  • May trigger similar investigations by attorneys general in other states
  • Signals that cryptocurrency-adjacent corporate restructuring (bankruptcy → rebranding) will not shield companies from liability for past failures

  • ---


    ## The Corporate Restructuring Question


    A notable element of this case is that the lawsuit targets Chrome Holding Co., the entity through which 23andMe has reorganized. In March 2024, 23andMe filed for bankruptcy protection following significant stock price decline and declining consumer confidence post-breach. The company subsequently emerged under a new corporate structure.


    California's decision to pursue the rebranded entity suggests that state regulators will not permit companies to escape accountability through corporate restructuring. This has important implications: companies cannot simply rebrand or reorganize to shed liability for past security failures and regulatory violations.


    ---


    ## What This Means for Users and the Industry


    For 23andMe Users:

    Millions of customers who submitted genetic samples to 23andMe now face an uncertain landscape. Their genetic information remains exposed through breaches, and the company's financial instability creates ongoing questions about long-term data stewardship and storage practices. Users affected by the breach should consider identity theft protection, genetic privacy monitoring services, and consulting with legal counsel about participation in class action settlements.


    For the Genetic Testing Industry:

    This lawsuit signals that regulators expect genetic testing companies to implement enterprise-grade security for consumer data. Other direct-to-consumer genetic testing providers—including MyHeritage, Ancestry, and others—should anticipate similar regulatory scrutiny and may face pressure to publicly demonstrate enhanced security practices.


    For Healthcare and Biotech Companies:

    The enforcement action reinforces that regulators and courts will hold companies accountable when they fail to protect sensitive health data, regardless of corporate structure or profitability.


    ---


    ## Legal and Regulatory Implications


    The lawsuit leverages California's strong data privacy laws, including provisions of the California Consumer Privacy Act (CCPA) and California's broader consumer protection statutes. If successful, the state could seek:


  • Civil penalties for each violation (potentially in the hundreds of millions)
  • Restitution to affected consumers
  • Injunctive relief requiring 23andMe to implement specific security standards
  • Ongoing regulatory oversight and audit requirements

  • This case is also watched closely by privacy advocates and regulators nationwide as a test of whether states can effectively enforce accountability against technology companies that mishandle sensitive personal data.


    ---


    ## HackWire Analysis


    The California lawsuit against 23andMe represents a critical inflection point in how regulators approach genetic data privacy and corporate accountability. What's significant here is not merely that a breach occurred—security incidents happen in every industry—but rather that a major company treated exceptionally sensitive genetic information with security controls that would be considered inadequate even for routine customer databases.


    The timing of this enforcement action is particularly important. The lawsuit suggests that California regulators have concluded their investigation and determined that 23andMe's failures were not merely technical or accidental, but systemic and preventable. The company's pivot to bankruptcy restructuring and rebranding appears to have hardened, rather than softened, regulatory resolve. Courts and regulators are signaling that corporate reorganization is not a liability shield.


    There is also a pattern recognition element: 23andMe is not the first high-profile company to suffer a major breach and subsequently attempt to minimize accountability. The difference here is that California has moved beyond pressure campaigns and class actions to formal enforcement. This establishes a higher bar for genetic testing and biotech companies.


    The hidden risk in this story is what happens if 23andMe (now Chrome Holding Co.) lacks resources to fund both remediation obligations *and* ongoing operations. Bankruptcy protections and corporate restructuring may have reduced the company's capital position, creating a scenario where regulatory penalties cannot be fully satisfied or where customer refunds for data compromises become impossible. This highlights a critical gap: there may be insufficient mechanisms to ensure that companies harmed by security failures can actually be made whole.


    For defenders in the genetic testing and healthcare biotech space, the implication is clear: genetic data demands genetic-grade security, not standard baseline protections. Organizations handling genetic information should conduct third-party security audits, implement mandatory multi-factor authentication, encrypt all data at rest and in transit, and maintain comprehensive audit logs of all data access. — HackWire Editorial


    ---


    ## Recommendations for Organizations and Individuals


    For Organizations Handling Genetic Data:

  • Conduct comprehensive third-party security audits to identify gaps
  • Implement multi-factor authentication across all systems, particularly for databases containing personal genetic information
  • Encrypt all sensitive data using current industry-standard algorithms
  • Maintain detailed access logs and implement intrusion detection systems
  • Develop and regularly test incident response and breach notification procedures
  • Ensure board-level oversight of data security practices
  • Consider cyber liability insurance that covers data breach costs

  • For Consumers:

  • Review whether you've submitted genetic samples to 23andMe or other direct-to-consumer genetic testing services
  • Monitor credit reports and financial accounts for signs of identity theft
  • Consider genetic privacy services that monitor unauthorized access to genetic databases
  • Review privacy policies of genetic testing companies before submitting samples
  • Participate in class action settlements if eligible

  • ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Data Privacy](https://www.hackwire.news/category/data-privacy)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)