California Sues 23andMe for 2023 Data Breach Impacting Millions

Spread the love



Chrome Holding Co., previously known as 23andMe, is under legal scrutiny following a lawsuit initiated by California Attorney General Rob Bonta. This lawsuit stems from a significant security breach in 2023, which compromised the sensitive data of millions of individuals. Bonta alleges that the company misled its customers and failed to adequately safeguard their “sensitive personal information and genetic data related to their health, genetic predispositions and risk factors, biological relatives, ancestry, and ethnicity.” According to the lawsuit, the breach affected 7 million users nationwide, including 855,541 residents of California.

23andMe, a provider of DNA testing kits that allow consumers to discover their ancestral background and genetic health risks, acknowledged in 2023 that malicious actors accessed user accounts through a method known as credential stuffing. Bonta contends that companies, especially those handling genetic information, should be vigilant against such prevalent cyberattack techniques.

In this specific incident, the hacker utilized credentials obtained from earlier data breaches, including a notable attack on MyHeritage, another genealogy platform that collaborated with 23andMe. Bonta points out that 23andMe was aware of the MyHeritage breach but failed to take precautions to prevent users from reusing compromised credentials. This oversight is particularly significant as 23andMe had encouraged its users to establish accounts with MyHeritage.

Credential stuffing was not the sole method that enabled these cybercriminals to access sensitive information. After breaching 14,000 accounts using this technique, the attackers exploited a vulnerability within the website’s DNA Relatives feature to access additional user data. Bonta emphasized that the company’s security measures were alarmingly insufficient, allowing hackers to remain undetected within the system for five months. He noted that the investigation only began after the criminals had already started selling the stolen data on the dark web and were demanding ransom payments.

See also  This Alexa-Enabled Roomba Robot Vacuum and Mop Will Clean Up Your Home and Its Already Almost Half off

Bonta criticized 23andMe for withholding essential details when notifying customers about the breach. He stated that the company minimized the severity of the stolen data and claimed that the DNA Relatives feature was “essentially public,” all while secretly negotiating with the perpetrators, who highlighted the sensitive nature of the dataset, including information about Asian American and Pacific Islander individuals, as well as Jewish users.

“The sale of this data on the dark web occurred during a time of increasing anti-Asian American and Pacific Islander sentiments and antisemitic violence — and explicitly drew attention to the deeply personal and identifying nature of that information,” Bonta remarked. “This situation is both troubling and exceptionally dangerous.”

In March 2025, 23andMe filed for bankruptcy. As reported by AP, the company was also facing a class-action lawsuit alleging it failed to protect its customers. A judge managing the bankruptcy proceedings had approved a $50 million settlement earlier this year.

best barefoot shoes

For the original content and additional images used in this article, please visit the source. We acknowledge their authorship and utilize these materials solely for informative purposes with appropriate attribution.

  • Daniel Mercer

    Daniel Mercer is an insightful author and technology enthusiast, known for his engaging contributions to Social Schmuck. With a knack for simplifying complex tech concepts, he covers a wide range of topics, from emerging innovations to the impact of technology on daily life. Daniel is passionate about fostering understanding and dialogue around the ever-evolving digital landscape, making technology accessible and relevant to all readers.

    Related Posts

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI Money Robot Submitter Review 2026 Money Robot Submitter Review: Powerful Backlink Automation — But Is It Worth…

    Read more

    AI Models Oversee Simulated Society Amid Crime Spree

    Spread the love

    Spread the love Share It: ChatGPT Perplexity WhatsApp LinkedIn X Grok Google AI If you have concerns that advanced artificial intelligence might trap humanity in a Matrix-like simulation, you can…

    Read more

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    Money Robot Submitter Review 2026: Is This Backlink Automation Tool Worth It?

    California Sues 23andMe for 2023 Data Breach Impacting Millions

    California Sues 23andMe for 2023 Data Breach Impacting Millions

    Blocked Twitter Account: Delhi High Court Denies Immediate Relief

    Blocked Twitter Account: Delhi High Court Denies Immediate Relief

    Subscription Tiers for Instagram, Facebook, and WhatsApp Launched by Meta

    Subscription Tiers for Instagram, Facebook, and WhatsApp Launched by Meta

    $11K Gift Sparks Social Media Reactions About Parenting

    $11K Gift Sparks Social Media Reactions About Parenting

    AI Models Oversee Simulated Society Amid Crime Spree

    AI Models Oversee Simulated Society Amid Crime Spree

    Subscription Strategy Expansion: Meta Introduces Paid Tiers on Facebook, Instagram, and WhatsApp

    Subscription Strategy Expansion: Meta Introduces Paid Tiers on Facebook, Instagram, and WhatsApp

    Accidental Bedroom Breakthrough: The Untold Story

    Accidental Bedroom Breakthrough: The Untold Story

    Moon Phase Today: What to Expect on May 29, 2026

    Moon Phase Today: What to Expect on May 29, 2026

    Teen Social Media Bans Grow Amid Limited Evidence

    Teen Social Media Bans Grow Amid Limited Evidence