The Legal Action Against 23andMe
The office of Rob Bonta, California’s attorney general, is taking legal action against 23andMe due to the data protection shortcomings that resulted in the genetics company’s significant breach in 2023. Bonta and his team assert [PDF] that 23andMe did not apply sufficient security measures to safeguard the sensitive information it held and misled consumers regarding the incident’s severity afterward.
“23andMe amassed genetic information from millions of individuals, did not fulfill its duty under California law to protect that data, and subsequently deceived customers about the seriousness of its 2023 data breach,” Bonta stated on Thursday. “Our investigation revealed that the company neglected to take fundamental precautions to secure users’ information – which includes sensitive personal data, family histories, and health conditions of consumers.”
“The trade of this data on the dark web occurred during a surge in anti-Asian American and Pacific Islander and antisemitic hatred and violence – highlighting the deeply personal and identifying characteristics of that information. This is troubling and extraordinarily perilous. Today, my office is filing suit against 23andMe for its blatant failure to adhere to California law.”
The Transfer of Ownership
The suit has been lodged against Chrome Holding Co., which was previously named 23andMe. TTAM Research Institute acquired 23andMe’s assets the previous year. TTAM Research Institute was founded by Anne Wojcicki, who also served as 23andMe’s CEO at the time of the breach and is one of the company’s co-founders.
The completion of the nonprofit’s acquisition of 23andMe’s assets occurred on July 14, 2025, when it committed to operating 23andMe in a charitable manner, utilizing its data to promote medical research and education. 23andMe continues to function as before, collecting customers’ saliva samples and providing entertaining insights, like the percentage of Neanderthal ancestry or whether their DNA influences their preference for cilantro in their meals.
‘Alarming’ Aspects
In the announcement of the lawsuit, Bonta’s office used “alarming” repeatedly to characterize the circumstances that took place before and after 23andMe’s significant breach. To summarize, a cybercriminal known as Golem appeared on a forum in 2023, claiming to have access to a vast amount of data belonging to millions of 23andMe customers.
Subsequent investigations by regulators revealed that Golem had only accessed approximately 14,000 accounts, but through 23andMe’s DNA relatives feature, which enables users to connect with others who share similar DNA percentages, the hacker managed to gain insights into nearly 7 million customers’ details. It also became clear that 23andMe took five months to detect the breach, and the roughly 14,000 accounts compromised were the result of credential-stuffing attacks.
The Blame Allocation
What ensued was a complex situation of blame. 23andMe’s choice to hold customers responsible for reusing credentials instead of acknowledging that it should have enforced 2/MFA on all accounts by default was met with significant backlash. Currently, 23andMe still permits customers to use its service without 2/MFA, though it regularly prompts those who have yet to set it up.
Meanwhile, regulators pointed out that the company’s security measures were far from flawless, while cybersecurity experts were split on the issue. Many agreed that fault lay with both parties. Then, fines and settlements followed. The UK’s Information Commissioner imposed a £2.3 million ($3.09 million) penalty on the company in June 2025, three months after the bankruptcy declaration.
In its conclusion, it supported the findings of US authorities from 2023, accusing the company of inadequate password standards. The Information Commissioner criticized 23andMe for its delay in identifying the breach and its failure to establish protections against bulk genetic data downloads. Moreover, 23andMe reached a $30 million settlement in a class action lawsuit in 2024.
Deceptive Communications
Bonta’s office claimed that 23andMe’s communications with customers were “deceptive and excluded or misrepresented crucial information.” “While 23andMe reassured the public that no data security incident had occurred within its systems and minimized the sensitivity of the stolen data by asserting that the information from the ‘DNA Relatives’ feature was essentially public, and sought to transfer responsibility for the breach to its customers, 23andMe was concurrently negotiating and paying a ransom to the adversary in exchange for, among other considerations, the removal of compromising information about the breach that had been online and details about various 23andMe security flaws, including those exploited during the data breach.”
Response from 23andMe
GadgetLad reached out to 23andMe’s public relations representatives for a statement. We only received a reply from the 23andMe Research Institute, which, despite managing requests addressed to the sole press contact for the 23andMe platform, distanced itself from Chrome Holding, which, like TTAM Research Institute, lacks a public-facing contact. It also did not assist us in getting in touch with 23andMe’s operator.
The institute stated: “The 23andMe Research Institute is a newly created independent nonprofit entity and is not implicated in the incidents outlined in the California Attorney General’s complaint against Chrome Holding Co., previously known as 23andMe. The lawsuit concerns events and operations related to the former commercial organization prior to the establishment of the 23andMe Research Institute. The institute was not involved in the complaint and has no role in the ongoing litigation.
“The 23andMe Research Institute is dedicated to promoting nonprofit scientific and health research with a strong emphasis on privacy, ethics, transparency, and responsible data management.”
Conclusion: DNA Challenges and Crises
So there you have it, everyone! A true debacle from the team at 23andMe, or whatever they go by these days. Keep in mind, when dealing with DNA, don’t hide the keys under the doormat.