California’s Attorney General has filed a lawsuit against Chrome Holding, the successor firm to DNA testing firm 23andMe, following an investigation into a major security incident that exposed the DNA data of nearly seven million users in 2023. Rob Bonta contends that 23andMe did not put in place basic security measures to safeguard sensitive customer data, such as genetic predispositions, risk factors, and details about biological relatives, ancestry and ethnicity. The lawsuit also asserts the company deceived customers about the seriousness of the incident. The case marks the most recent legal penalty for the genetic testing company, which has encountered international scrutiny and penalties following the breach, such as a £2.31 million fine from the Information Commissioner’s Office in the UK.
The scale of the security failure
The breach took place through a so-called “credential stuffing” attack, a method in which hackers leveraged passwords that had been compromised in previous, unrelated data breaches. The attackers used these compromised credentials to obtain unauthorised access to 23andMe accounts belonging to users who had recycled the same passwords across various services. This method of attack is considered relatively unsophisticated, yet 23andMe’s failure to implement adequate security measures left millions of users at risk. The company did not employ sufficient authentication or verification protocols during the login process, a fundamental protection that could have prevented the unauthorised access.
The inquiry by California’s Attorney General revealed that 23andMe took insufficient steps to safeguard one of the most sensitive categories of personal data available. Under UK data protection law, genetic data is classified as a protected category requiring enhanced protections and safeguards due to its highly sensitive nature. The breach’s impact went beyond the United States, with the UK’s ICO confirming that personal data belonging to 155,592 British residents had been accessed. The global reach of the incident highlights the seriousness of the security failure and the company’s responsibility to safeguard data across multiple jurisdictions.
- Hackers leveraged stolen passwords from earlier unrelated data breaches
- 23andMe failed to put in place adequate authentication and verification measures
- Approximately seven million users had exposed genetic information on a global scale
- Genetic data requires strengthened legal safeguards under current UK law
How hackers gained access to confidential data
The 2023 security incident that exposed the genetic data of nearly seven million 23andMe users was carried out through a fairly simple yet devastatingly effective approach called credential stuffing. Rather than implementing complex exploitation strategies, threat actors leveraged previously stolen credentials in past compromises affecting other businesses and websites. These pilfered login details were then routinely tried against 23andMe accounts, exploiting a common human behaviour: the repeated use of the same passwords across different websites and applications. This simple method proved remarkably successful on 23andMe’s insufficient security systems.
What constituted this attack notably harmful was the confidential quality of the data under compromise. Genetic information serves as one of the highly intimate and immutable forms of data an individual can possess, exposing disease susceptibilities, ancestry, racial identity, and information about blood relations. The breach was worsened when threat actors intentionally distributed the stolen data on the hidden networks, specifically highlighting that it was sourced from Asian American Pacific Islander and Jewish users. This deliberate method raised serious concerns about potential discrimination and personal dangers during a period defined by increasing hate crimes against these groups.
Login credential misuse explained
Credential stuffing is a cyber attack technique in which cybercriminals systematically input large volumes of stolen login credentials to target websites, wagering that people have recycled the identical login information across various services. This method exploits typical user habits and poor password management practices rather than necessitating advanced technical skills. Once intruders penetrate into user accounts through credential stuffing, they can harvest the confidential details contained in. 23andMe’s failure to implement multi-factor authentication or alternative authentication methods made accounts susceptible to this fairly basic but remarkably successful attack vector.
International regulatory action and penalties
The 2023 data breach has spurred substantial regulatory examination across multiple jurisdictions, with international regulatory bodies taking action against 23andMe for its failure to adequately protect confidential genetic records. The company has come under significant pressure for not implementing basic security measures such as two-factor verification and thorough account authentication protocols. These failures created critical vulnerabilities, allowing hackers to access millions of user accounts through relatively unsophisticated attacks. Regulators have emphasised that genetic information constitutes a unique type of individual records requiring heightened protections under privacy legislation, making 23andMe’s safeguarding shortcomings all the more egregious.
The UK’s Information Commissioner’s Office (ICO) imposed a penalty of £2.31 million against the company, following an investigation that uncovered 155,592 UK residents’ data had been accessed during the breach. The ICO’s investigation, carried out jointly with Canada’s privacy commissioner, determined that 23andMe had violated UK privacy legislation by failing to implement suitable identity verification and security controls. The watchdog’s findings underscored widespread deficiencies in the company’s technical security framework and its approach to protecting customer privacy. Currently, California’s Attorney General has launched legal action against Chrome Holding, 23andMe’s successor company after the company entered bankruptcy, claiming the predecessor company both failed to safeguard data but furthermore deceived consumers regarding how serious the breach was.
| Jurisdiction | Action taken |
|---|---|
| United Kingdom | Information Commissioner’s Office fined 23andMe £2.31 million for failing to implement adequate security measures and protect 155,592 UK residents’ data |
| Canada | Privacy Commissioner coordinated investigation with the UK ICO into 23andMe’s security failures and data protection violations |
| California, USA | Attorney General Rob Bonta filed lawsuit against Chrome Holding, alleging predecessor 23andMe failed to protect customer data and misled consumers about breach severity |
Extended implications for genetic privacy
The 23andMe breach followed by regulatory actions have uncovered critical weaknesses in how genetic information is safeguarded across the industry. Genetic data represents one of the most confidential categories of personal data, disclosing not only an individual’s genetic health markers but also details about biological family members and ancestral background. The circumstance that stolen data was deliberately sold on the dark web targeting Asian American Pacific Islander and Jewish users adds a deeply troubling dimension, illustrating how genetic information can be exploited for discriminatory ends during times of increased social unrest and hate incidents.
The case has sparked urgent concerns about whether existing data protection frameworks are sufficiently robust to handle the unique risks posed by genetic information. Companies working within this space must now contend with heightened expectations from regulators globally, who are increasingly treating genetic data as requiring special category protections. The California lawsuit constitutes a significant intensification in enforcement action, signalling that regulators will not accept inadequate security measures or misleading communications about data breaches. This shift is expected to reshape industry standards and force genetic testing companies to commit significant resources in security infrastructure and transparency practices.
- Genetic data requires dedicated safeguards due to its sensitive and irreversible nature
- Credential stuffing attacks demonstrate the critical need for multi-factor authentication and proper verification
- Dark web sales focused on particular communities based on ethnicity and faith, prompting worries about unfair treatment
- International regulatory coordination enhances enforcement against major data protection violations
- Companies must balance innovation with strong protections and clear incident disclosure
The company’s challenging route to insolvency
23andMe’s slide into financial troubles represents a striking change in fortunes for a organisation that once held significant investor confidence and celebrity support. At its zenith, the company’s share price climbed to $300, and it attracted well-known customers such as Snoop Dogg, Oprah Winfrey, and Eva Longoria. The company, founded by Anne Wojcicki—sibling of the former YouTube boss Susan Wojcicki and former wife of Google co-founder Sergey Brin—had established itself as a leading player in customised DNA testing. Yet, growing operational difficulties and harm to its standing from the 2023 data breach substantially eroded investor faith and consumer trust.
The company’s bankruptcy filing last year marked a critical turning point, forcing it to divest operations through a court-supervised process. This shift created additional complications for users, many of whom experienced problems deleting their accounts during the reorganisation phase. Concerns arose about possible information transfers to insurers, with users fearing their genetic information could be applied to reject claims or increase policy costs. The later rebrand as Chrome Holding represented an attempt to distance the company from its problematic history, yet the enforcement consequences from the data incident has grown increasingly severe, with authorities worldwide taking legal measures that jeopardise the viability of the business model itself.