• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens

3

The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens

3

The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish
CybersecurityLawsuit

California sues 23andMe over alleged ‘lax’ data security that failed to protect nearly 7 million users’ data in 2023 breach

By
Jaimie Ding
Jaimie Ding
and
The Associated Press
The Associated Press
Down Arrow Button Icon
By
Jaimie Ding
Jaimie Ding
and
The Associated Press
The Associated Press
Down Arrow Button Icon
May 29, 2026, 9:30 AM ET
Bonta stands at podium and gestures with one hand.
California Attorney General Rob Bonta speaks during a press conference in Los Angeles on Friday, March 20, 2026. Sarah Reingewirtz—MediaNews Group/Los Angeles Daily News via Getty Images

California’s attorney general sued the genetic testing company formerly known as 23andMe on Thursday, alleging it failed to protect sensitive user data in a 2023 breach that affected nearly 7 million people across the country.

Recommended Video

Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March. 23andme is known for its direct-to-consumer DNA test kits that provided customers information on their ancestry and genetic predispositions for certain health conditions.

The lawsuit calls for various civil penalties against 23andMe and injunctions blocking the company from further violations of California’s privacy protection laws.

The company has acknowledged that it suffered a major security breach in 2023 that resulted in about 14,000 accounts accessed, through which they were able to steal the data of nearly 7 million customers. The cyberattack utilized “credential stuffing,” which takes advantage of customers’ tendency to use weak or common passwords or reuse passwords between multiple accounts.

Bonta’s office said this was a well-known attack that businesses should know to guard against. The attackers used stolen user account credentials including ones from a massive data breach in October 2017 that affected MyHeritage, one of 23andMe’s former partners. After that breach, 23andMe did not take common protocols such as asking customers to reset their passwords or use multifactor authentication.

23andMe did not immediately respond to an emailed request for comment.

“23andMe’s security measures were so lax that the threat actor was able to operate undetected within 23andMe’s systems for over five months, and remarkably, 23andMe only began investigating after the threat actor offered the stolen user data for sale on the dark web and reached out to 23andMe to demand a ransom,” prosecutors said in the complaint.

In October 2023, the stolen data appeared for sale on the dark web, with the poster specifically touting that about 1.1 million consumers’ data belonged to Asian-Pacific Islander and Ashkenazi Jewish users.

“The sale of this data on the dark web took place amidst a period of mounting anti-Asian American and Pacific Islander and antisemitic hate and violence,” Bonta said in a press release. “This is disturbing and incredibly dangerous.”

Some of the data stolen included raw genetic data, health reports, DNA shared with other relatives, and locations and birth years of relatives.

The lawsuit says that after notifying the public about the breach, 23andMe continued to mislead consumers about the severity of the breach and the company’s role in it.

The company has said it only found out about the breach in October 2023 when the stolen data was posted for sale on the dark web. However, the lawsuit said the company failed to properly investigate red flags that appeared months earlier, such as a “suspicious spike in user login attempts” in July and a Reddit post discussing a possible breach and sale of user data in August.

Genetic data requires “one of the highest levels of protection” and California law “mandates a heightened legal obligation” to protect it, the lawsuit said.

Bonta also intervened to ensure customers’ genetic data wouldn’t be mishandled during 23andMe’s Chapter 11 bankruptcy and asset sale, arguing that California’s Genetic Information Privacy Act required companies to obtain opt-in consent from customers before selling their genetic information to third parties. However, the sale was allowed to proceed.

In 2024, 23andMe agreed to pay a $30 million settlement in a class-action lawsuit accusing the company of failing to protect customers whose personal information was exposed in the breach. The amount was raised to $50 million to resolve most U.S. customer claims and received final approval in January by a federal judge overseeing 23andMe’s bankruptcy.

In 2001, Fortune first convened the smartest people we know, bringing together CEOs and founders, builders and investors, thinkers and doers. Since then, Fortune Brainstorm Tech has been the place where bold ideas collide. From June 8–10, we will return to Aspen—where it all began—to mark 25 years of Brainstorm. Register now.
About the Authors
By Jaimie Ding
See full bioRight Arrow Button Icon
By The Associated Press
See full bioRight Arrow Button Icon

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Cybersecurity

Bonta stands at podium and gestures with one hand.
CybersecurityLawsuit
California sues 23andMe over alleged ‘lax’ data security that failed to protect nearly 7 million users’ data in 2023 breach
By Jaimie Ding and The Associated PressMay 29, 2026
1 hour ago
t
CommentaryCoding
Girls Who Code CEO: 70% of teen girls want to work in cybersecurity. We’re losing them before they start
By Tarika BarrettMay 29, 2026
2 hours ago
Geordie AI cofounders Henry Comfort (left), Benji Weber (center), and Hanah Darley.
AIVenture Capital
Exclusive: Geordie AI raises $30 million Series A to be ‘air traffic control’ for your company’s AI agents
By Jeremy KahnMay 28, 2026
1 day ago
The U.K.’s top spy says the window to stay ahead of China and Russia is narrowing and cybersecurity needs to become ‘10 times more urgent’
CybersecurityIntelligence
The U.K.’s top spy says the window to stay ahead of China and Russia is narrowing and cybersecurity needs to become ‘10 times more urgent’
By Marco Quiroz-GutierrezMay 27, 2026
2 days ago
is
Commentaryregulation
We don’t imprison humans preemptively based on the capability to commit crime. Why regulate AI that way?
By Ion StoicaMay 27, 2026
2 days ago
sa
Politicsimpeachment
How $580,000 hidden under a sofa cushion became a constitutional crisis in South Africa
By Gerald Imray and The Associated PressMay 26, 2026
3 days ago

Most Popular

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
8 days ago
As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens
Magazine
As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens
By Emma HinchliffeMay 27, 2026
2 days ago
The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish
Environment
The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish
By Dorany Pineda, Brittany Peterson and The Associated PressMay 27, 2026
2 days ago
Jamie Dimon said the American Dream was slipping away. JPMorgan just put $40 million on the table to fix it
Banking
Jamie Dimon said the American Dream was slipping away. JPMorgan just put $40 million on the table to fix it
By Nick LichtenbergMay 27, 2026
2 days ago
Current price of oil as of May 28, 2026
Personal Finance
Current price of oil as of May 28, 2026
By Joseph HostetlerMay 28, 2026
1 day ago
As AI slashes white-collar jobs, Salesforce CEO Marc Benioff says almost no one is being hired—except in sales
Success
As AI slashes white-collar jobs, Salesforce CEO Marc Benioff says almost no one is being hired—except in sales
By Emma BurleighMay 28, 2026
23 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.