California Attorney General Rob Bonta has filed a lawsuit against 23andMe, now known as Chrome Holding Co., accusing the company of failing to protect customers’ sensitive genetic and personal information properly.

The lawsuit is linked to a major 2023 data breach that exposed the information of nearly 7 million customers, including 855,541 people in California. The incident first became public in October 2023, when threat actors began offering stolen 23andMe records for sale and leaked samples of the data to prove that the information was real.

23andMe later confirmed that the leaked data was genuine. The company said the attackers had accessed accounts through a credential-stuffing attack, where hackers use previously leaked usernames and passwords to break into accounts that reuse weak or exposed login details.

It later became clear that the attackers had taken data from users who had opted into 23andMe’s “DNA Relatives” feature. They were then able to access information connected to a much larger group of accounts that did not directly use the feature.

In total, the breach exposed data from about 6.9 million customers. The stolen information included genetic data, health predisposition details, ancestry and ethnicity information, biological relatives, and DNA matches.

By the end of 2023, 23andMe was already facing several lawsuits over the incident. In early 2024, data protection authorities also launched investigations that later resulted in multi-million-dollar fines. The pressure from these legal and financial problems eventually led the company to file for bankruptcy.

READ
Coca-Cola Confirms Data Stolen in Fairlife Ransomware Attack

The latest lawsuit from Attorney General Bonta claims that 23andMe failed to put reasonable protections in place against credential-stuffing attacks. It also says the company missed several chances to detect the intrusion and failed to catch a coding error in the DNA Relatives feature that contributed to the large-scale exposure of customer data.

Bonta also accused 23andMe of making misleading public statements before and after the breach. Before the incident, the company claimed that its security met high standards. After the breach, it allegedly sought to downplay the incident’s seriousness by claiming that much of the exposed data was already public and by blaming customers for reusing passwords.

The lawsuit says these actions violated several California laws, including the California Genetic Information Privacy Act, the California Reasonable Data Security Law, the California Consumer Privacy Act, the False Advertising Law, and the Unfair Competition Law.

The complaint asks the court to stop 23andMe from committing further violations and seeks statutory penalties ranging from $1,000 to $7,500 per violation, depending on the case.

The Attorney General’s office also noted that the bankruptcy dispute over the proposed sale of Californians’ genetic data and biological materials is being handled as a separate matter.


Buy ExpressVPN with PayPal or Credit Card

Advertisement