23andMe sued: California files suit over massive DNA theft
I'm LongbridgeAI, I can summarize articles.California Attorney General Rob Bonta filed a lawsuit against Chrome Holding Co., the entity behind 23andMe, alleging negligence in a massive 2023 data breach. Hackers accessed nearly seven million users' genetic and ancestry data for five months. The state seeks civil penalties, highlighting the permanent nature of compromised biological information and holding the company accountable for failing to protect sensitive user data despite known vulnerabilities.
The genetic data company 23andMe is once again at the center of a legal storm — and this time, it’s the state of California doing the suing.
California Attorney General Rob Bonta filed a lawsuit Thursday in San Francisco Superior Court targeting Chrome Holding Co., the corporate name 23andMe operated under during its bankruptcy proceedings last year. The case strikes at the heart of one of the most alarming data breaches in the history of consumer health technology — and raises urgent questions about what companies owe the people who hand over their most intimate biological information.
What 23andMe Allegedly Let Happen
The lawsuit paints a disturbing picture of negligence that stretched across months. Hackers reportedly moved freely inside 23andMe’s systems for five full months in 2023, quietly harvesting data tied to nearly seven million users. During that same window, the company reportedly detected more than one million login attempts targeting a single customer account in a single day — and still did nothing.
That inaction, the state contends, was not just an oversight. It was a pattern. 23andMe allegedly told the public that everything was under control while stolen data — including ancestry breakdowns and genetic health profiles — was already being sold on the dark web. The company’s DNA Relatives feature, which allows users to connect with biological relatives, was among the tools exploited to access profile information without authorization. Users who had opted into that feature had no idea their data was circulating in criminal marketplaces while the company issued reassurances.
The Fallout From the 23andMe Breach
The 2023 breach set off a cascading series of consequences for 23andMe. In its aftermath, the company scrambled to implement two-step verification and forced password resets across its entire user base. It also agreed to pay $30 million in a class-action settlement tied directly to the incident — a significant financial blow for a company already struggling to stay solvent.
Then came bankruptcy. Last July, a federal court signed off on the $305 million sale of 23andMe to TTAM Research Institute, a nonprofit organization led by former CEO Anne Wojcicki — the same executive who had helmed the company through its rise and eventual collapse. The brand may have survived the fire sale, but the legal liabilities appear to have followed it into its next chapter.
A Pioneer That Lost Its Way
Founded in San Francisco in 2006, 23andMe was once celebrated as a trailblazer — one of the first companies to bring genetic testing directly to consumers at scale. Its saliva-based DNA kits promised users a revealing window into their ancestry and potential health risks, democratizing information that had once been limited to clinical settings and expensive laboratory work.
But 23andMe never cracked the code on turning widespread curiosity into a consistently profitable business. Years of mounting losses, a failed pharmaceutical pivot, and growing public skepticism about how genetic data is stored, shared, and potentially monetized slowly eroded trust in the brand. The 2023 breach was less a sudden catastrophe than the final, defining blow to a company already teetering on the edge.
What the 23andMe Lawsuit Is Seeking
The California lawsuit seeks multiple civil penalties against Chrome Holding Co. and, by extension, the broader 23andMe operation. The state’s case underscores a growing concern among regulators that companies handling sensitive biological data must be held to a significantly higher standard — especially when that data includes information as intimate and irreplaceable as a person’s genetic makeup.
Unlike a stolen credit card number that can be cancelled and reissued, genetic data is permanent. Once compromised, it cannot be reset or recovered. A person’s ancestry, inherited health vulnerabilities, and biological family connections exist in that data — information that carries consequences not just for the individual, but potentially for their relatives as well. That reality makes the alleged failures at 23andMe especially consequential — and, in California’s view, especially deserving of accountability.
For the millions of users whose DNA now exists somewhere in the digital underground, the lawsuit represents an overdue reckoning. Whether it ultimately delivers meaningful justice — or simply adds another chapter to a long story of broken digital trust — remains to be seen.
Source: ABC News
