Regulation2 min read

California Sues 23andMe Over 7 Million-User DNA Breach

May 31, 2026Synthesized from 1 source: Engadget

California has filed a lawsuit against the company formerly known as 23andMe over a 2023 data breach that exposed the genetic, health, and ancestry data of nearly 7 million people, and the case reveals how badly the company mishandled both the security failure and its aftermath.

California's attorney general filed a lawsuit this week against the company formerly known as 23andMe, a DNA testing service that went bankrupt in March 2025. The case is about a 2023 data breach that exposed the genetic profiles, health risk data, and ancestral information of nearly 7 million people. About 855,000 of them were California residents.

The mechanics of the attack are worth understanding because they apply far beyond genetics. Hackers used a method called credential stuffing: they took usernames and passwords stolen in a previous breach at a partner site, MyHeritage, and tried those same combinations on 23andMe. It worked. The lawsuit says 23andMe knew about the MyHeritage breach and never checked whether its own users had reused those passwords. It had even encouraged users to sign up for MyHeritage accounts.

From only 14,000 accounts broken into that way, the attackers then used 23andMe's own DNA Relatives feature, which shows users which other members they share DNA with, to pull data on nearly 7 million connected people. The whole operation ran undetected inside the company's systems for five months. The company only started investigating after the stolen data was already being sold online, with the sellers specifically advertising that it included records of Jewish and Asian American users.

The attorney general's office says the company then made things worse by downplaying what had happened. It called the stolen information from the DNA Relatives feature "essentially public" while privately negotiating with the hackers. It did not require users to change their passwords or turn on two-step verification until October and November 2023, months after the breach began.

The company is now a shell. Its actual assets, including all the genetic data it had collected from more than 15 million customers, were sold in July 2025 to a nonprofit called the TTAM Research Institute, led by 23andMe's own co-founder and former CEO Anne Wojcicki, for $305 million. The entity being sued, Chrome Holding Co., is essentially a legal remnant managing the bankruptcy wind-down. Civil penalties, if awarded, would have to be collected through that bankruptcy process.

The UK's data regulator also fined the company about $3 million in June 2025 for the same breach, citing inadequate password requirements and failure to detect the attack promptly.

There is a broader point here that matters for any business that holds customer data. The attack required no advanced technical skill. It worked because users reuse passwords across services, and 23andMe had no real-time monitoring to catch the unusually high volume of login attempts. In fact, the lawsuit says the company detected more than one million login attempts to a single account in a single day and still did not act.

Genetic data sits in a different category from most other sensitive information. You can cancel a credit card. You cannot change your DNA. Once that data is out, it implicates not just the person who submitted a sample but their biological relatives, including people who never used the service. The 23andMe case is the first major test of how regulators treat this kind of irreversible exposure, and based on what California is now seeking, the legal liability attached to holding genetic data is becoming very real.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable