California’s Attorney General has filed a lawsuit against Chrome Holding, the successor company to DNA testing firm 23andMe, following an inquiry regarding a major security incident that exposed the genetic information of approximately 7 million users in 2023. Rob Bonta contends that 23andMe failed to implement fundamental protective safeguards to safeguard sensitive customer data, including genetic predispositions, risk factors, and details about biological relatives, ancestry and ethnicity. The lawsuit also asserts the company deceived customers about the severity of the breach. The case marks the latest regulatory consequence for the genetic testing company, which has faced global oversight and penalties following the breach, including a £2.31 million fine from the Information Commissioner’s Office in the UK.
The extent of the security failure
The breach happened through a so-called “credential stuffing” attack, a method in which hackers leveraged passwords that had been compromised in previous, unrelated data breaches. The attackers deployed these compromised credentials to obtain unauthorised access to 23andMe accounts held by users who had reused the same passwords across various services. This method of attack is considered relatively unsophisticated, yet 23andMe’s failure to implement adequate security measures left millions of users vulnerable. The company did not utilise sufficient authentication or verification protocols during the login process, a basic safeguard that could have prevented the unauthorised access.
The investigation by California’s Attorney General uncovered that 23andMe failed to protect one of the most sensitive types of personal data available. Under UK data protection regulations, genetic data is designated as a protected category requiring heightened safeguards due to its highly sensitive nature. The breach’s impact extended beyond the United States, with the UK’s Information Commissioner’s Office verifying that personal information belonging to 155,592 British residents had been accessed. The global reach of the breach underscores the gravity of the security failure and the company’s obligation to safeguard data across multiple jurisdictions.
- Hackers utilised stolen passwords from earlier unrelated data breaches
- 23andMe failed to put in place adequate authentication and verification measures
- Nearly seven million users experienced exposure of genetic information on a global scale
- Genetic data demands strengthened legal safeguards under current UK law
How cybercriminals obtained sensitive information
The 2023 breach that revealed the DNA information of approximately seven million 23andMe users was executed through a relatively straightforward yet remarkably successful technique called credential stuffing. Rather than utilising sophisticated hacking methods, attackers exploited passwords breached in earlier incidents in previous, unrelated data breaches affecting other organisations and services. These pilfered login details were then routinely tried against 23andMe accounts, taking advantage of a typical user habit: the repeated use of the same passwords across different websites and applications. This low-tech approach proved strikingly efficient against 23andMe’s insufficient security systems.
What rendered this attack especially destructive was the confidential quality of the data being accessed. Genetic information represents one of the highly intimate and unchangeable types of data an individual can hold, exposing predispositions to diseases, family heritage, ethnicity, and information about blood relations. The breach was compounded when threat actors deliberately marketed the stolen data on the hidden networks, specifically highlighting that it was sourced from Asian American Pacific Islander and Jewish users. This selective strategy generated substantial alarm about possible prejudicial treatment and safety risks during a period marked by growing attacks against these populations.
Login credential misuse explained
Credential stuffing is a cyberattack method in which cybercriminals systematically input large volumes of compromised username and password combinations to victim websites, hoping that users have reused the matching passwords across multiple platforms. This approach capitalises on inherent human behaviour and weak credential handling rather than necessitating sophisticated expertise. Once intruders penetrate a user profile through credential stuffing, they are able to extract the sensitive personal information contained in. 23andMe’s inability to establish two-factor verification or other verification measures rendered accounts exposed to this relatively unsophisticated but remarkably successful attack vector.
International regulatory measures and penalties
The 2023 information breach has prompted substantial regulatory examination across various regions, with authorities worldwide pursuing measures against 23andMe for its inability to sufficiently safeguard sensitive genetic information. The company has attracted considerable scrutiny for neglecting to establish fundamental protective safeguards such as multi-factor authentication and thorough account authentication protocols. These oversights resulted in severe consequences, allowing hackers to access numerous user records through comparatively basic methods. Regulators have stressed that genetic data forms a special category of private data demanding enhanced safeguards under privacy legislation, making 23andMe’s security failures especially troubling.
The UK’s Information Commissioner’s Office (ICO) imposed a penalty of £2.31 million against the company, after an enquiry that uncovered 155,592 UK residents’ data had been accessed in the incident. The ICO’s probe, carried out jointly with Canada’s privacy commissioner, determined that 23andMe breached UK data protection law by failing to implement appropriate authentication and verification measures. The watchdog’s findings underscored systemic failures in the company’s technical security framework and its approach to protecting customer privacy. Now, California’s Attorney General has initiated proceedings against Chrome Holding, 23andMe’s parent organisation after the company entered bankruptcy, alleging the predecessor company not only failed to protect data but furthermore deceived consumers regarding how serious the breach was.
| Jurisdiction | Action taken |
|---|---|
| United Kingdom | Information Commissioner’s Office fined 23andMe £2.31 million for failing to implement adequate security measures and protect 155,592 UK residents’ data |
| Canada | Privacy Commissioner coordinated investigation with the UK ICO into 23andMe’s security failures and data protection violations |
| California, USA | Attorney General Rob Bonta filed lawsuit against Chrome Holding, alleging predecessor 23andMe failed to protect customer data and misled consumers about breach severity |
Wider implications for genetic privacy
The 23andMe breach followed by regulatory actions have exposed critical weaknesses in how genetic information is safeguarded across the industry. Genetic data constitutes one of the most sensitive types of personal data, exposing not only an individual’s health predispositions but also details about biological family members and ancestral background. The circumstance that stolen data was specifically marketed on the dark web aimed at Asian American Pacific Islander and Jewish users introduces a deeply disturbing element, illustrating how genetic information can be exploited for discriminatory ends during eras of elevated intergroup tension and hate-motivated violence.
The case has prompted urgent concerns about whether current data protection frameworks are adequately strong to handle the distinctive risks associated with genetic information. Companies operating in this space must now face heightened expectations from regulators globally, who are increasingly treating genetic data as demanding special category protections. The California lawsuit constitutes a significant escalation in enforcement action, signalling that regulators will no longer tolerate inadequate security measures or misleading communications about data breaches. This shift is expected to reshape industry standards and force genetic testing companies to invest substantially in security infrastructure and transparency practices.
- Genetic data requires dedicated safeguards due to its sensitive and irreversible nature
- Credential stuffing attacks demonstrate the importance of multiple authentication layers and thorough checks
- Dark web sales targeted particular communities based on ethnicity and faith, raising worries about unfair treatment
- International compliance cooperation enhances action on serious breaches of data safeguards
- Companies must reconcile new developments with robust security and transparent breach communication
The company’s troubled path to financial collapse
23andMe’s slide into financial troubles signals a striking change in fortunes for a firm that once enjoyed substantial investor backing and high-profile backing. At its zenith, the company’s stock price climbed to $300, and it drew high-profile customers such as Snoop Dogg, Oprah Winfrey, and Eva Longoria. The company, cofounded by Anne Wojcicki—sibling of the late YouTube boss Susan Wojcicki and former wife of Google co-founder Sergey Brin—had positioned itself as a trailblazer in bespoke genetic analysis. However, mounting operational challenges and reputational damage from the 2023 data breach substantially eroded investor faith and consumer trust.
The company’s bankruptcy filing in the previous year marked a critical turning point, forcing it to divest operations through a court-supervised process. This shift created further difficulties for users, many of whom experienced problems removing their profiles during the restructuring period. Concerns arose about possible information transfers to insurance companies, with users worried that their DNA data could be applied to reject claims or increase policy costs. The subsequent rebranding as Chrome Holding represented an attempt to distance the company from its problematic history, yet the enforcement consequences from the breach has grown increasingly severe, with authorities worldwide taking legal measures that threaten the long-term sustainability of operations.