:

CALIFORNIA SUES 23ANDME OVER 7M-USER DATA BREACH

SECURITY DESK2 MIN READ
FRI, MAY 29, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

California's Attorney General Rob Bonta filed a lawsuit against 23andMe following a 2023 data breach that compromised genetic and personal information belonging to 7 million users. The stolen data was subsequently sold on the dark web.

The Lawsuit Attorney General Bonta's action targets the DNA testing company for inadequate security practices and failure to protect consumer data. The suit alleges 23andMe violated California's consumer protection laws by not implementing reasonable safeguards for sensitive genetic information. The Breach The breach occurred in 2023 when unauthorized actors accessed user accounts through credential stuffing attacks. Hackers obtained genetic ancestry data, health predispositions, and personal information from millions of customers. The compromised data later appeared on dark web marketplaces. 23andMe's Response The company previously acknowledged the breach and took steps to reset passwords and implement additional security measures. 23andMe stated it notified affected users and cooperated with law enforcement. The company maintained that many users had weak passwords that contributed to account compromise. Legal Implications The lawsuit represents a significant enforcement action against a major consumer genetics company. California has prioritized data protection cases, particularly involving sensitive health information. The suit seeks civil penalties, restitution for affected consumers, and injunctive relief requiring stronger security protocols. Industry Context The case highlights ongoing tensions between the consumer genetics industry and regulators over data security standards. DNA testing services collect some of the most sensitive personal information available. Breaches at these companies raise particular concerns given the permanent nature of genetic data—unlike passwords or credit card numbers, DNA cannot be changed. Other genetic testing companies face similar scrutiny from state and federal regulators regarding data protection practices and third-party data sharing policies. The lawsuit reflects growing regulatory pressure on tech companies handling sensitive consumer data following major security incidents.

■ SOURCES

EngadgetBleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

9H AGOIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

9H AGOSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

9H AGOIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

9H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.