惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
B
Blog RSS Feed
D
DataBreaches.Net
L
LangChain Blog
月光博客
月光博客
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
V
Visual Studio Blog
美团技术团队
Jina AI
Jina AI
博客园 - 司徒正美
雷峰网
雷峰网
Last Week in AI
Last Week in AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
小众软件
小众软件
罗磊的独立博客
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta

California Attorney General Xavier Becerra - Press Releases

Attorney General Bonta Joins Law Enforcement Partners, Announces Results of Operation “Hands Down” Targeting Organized Criminal Activity in the Central Valley Attorney General Bonta Opposes Trump Administration’s Unlawful Effort to Restrict Access to Affordable Housing Attorney General Bonta Calls Out Trump Administration’s Breach of its Agreement Not to Restrict Access to Affordable Housing During Ongoing Litigation Attorney General Bonta Opposes Plan to Weaken Federal Protections for Retirement Investments Attorney General Bonta Conditionally Approves Proposed Transaction to Ensure Continued Access to Senior Care Services in Fresno County Attorney General Bonta Seeks Justice for Grieving Families with First DOJ-Sponsored Missing Persons Resource Fair Attorney General Bonta Supports FTC and U.S. DOJ Efforts to Strengthen Merger Review for Healthcare and Other Acquisitions Attorney General Bonta Celebrates U.S. Supreme Court Decision Upholding Workers’ Rights Attorney General Bonta Issues Statement on New State Law That Strengthens Election Safeguards Unlawful, Unconstitutional, and Undemocratic: Attorney General Bonta Stands with D.C. Residents Who Want National Guard Troops Off Their Streets Attorney General Bonta Secures Major Settlement with Predatory Real Estate Company MV Realty, Delivering Relief to Nearly 1,500 Homeowners Attorney General Bonta Opposes Trump Administration’s Attempt to Weaken Discrimination Protections for LGBTQ+ Americans in Federally Funded Programs Don’t Call It Kids’ Safety if Kids Aren’t Safe: Attorney General Bonta Joins Bipartisan Coalition in Opposing KIDS Act Attorney General Bonta Issues Consumer Alert on Price Gouging Following State of Emergency Declaration in Orange County Due to Chemical Incident Attorney General Bonta Announces Arrest of Sacramento Casino Conman Attorney General Bonta Opposes U.S. Department of Education’s Effort to Remove Reporting Requirements That Address Disparities for Students with Disabilities Attorney General Bonta Raises Concerns Over Donor-Advised Fund Restrictions Affecting Southern Poverty Law Center Attorney General Bonta Asks Court to Break Up Live Nation/Ticketmaster Attorney General Bonta Secures Strong Foundation, Settlement in California Concrete Merger California Department of Justice Investigating Tulare County Sheriff’s Department Officer-Involved Shooting Under AB 1506 Time’s Up: Attorney General Bonta Announces Felony Charges Against Southern California Jeweler for $1.5 Million Phantom Rolex Scheme Attorney General Bonta Throws Support Behind Colorado Amid Challenge to Its Social Media Warning Label Law Attorney General Applauds FTC’s Rulemaking on Unfair Food Delivery Fees Harming Consumers Attorney General Bonta Sues Trump Administration Over Attempt to Limit Student Loan Access for Healthcare Workers Time to Pay the Piper: Attorney General Bonta and Governor Newsom Secure Financial Penalties Against Huntington Beach in Housing Lawsuit Attorney General Bonta Opposes Trump Administration’s Proposed Rollback of National Emission Standards for Ethylene Oxide “Cruel, inhumano e inaceptable”: el fiscal general Bonta publica el quinto informe sobre las condiciones en los centros de detención de inmigrantes de California California Department of Justice Releases Proposed "Protecting Our Kids from Social Media Addiction Act (SB 976)” Regulations California Department of Justice Releases Report on Officer-Involved Shooting of Charles Towns Attorney General Bonta Responds to U.S. Supreme Court Decision Preserving Mifepristone Access
Attorney General Bonta Sues Chrome Holding Co., Formerly ...
Office of th · 2026-05-28 · via California Attorney General Xavier Becerra - Press Releases

OAKLAND — California Attorney General Rob Bonta today filed a lawsuit against Chrome Holding Co., formerly known as 23andMe, for failing to protect its customers’ sensitive personal information and genetic data related to their health, genetic predispositions and risk factors, biological relatives, ancestry, and ethnicity. In 2023, 23andMe experienced a data breach that affected nearly 7 million users across the United States, including 855,541 Californians. While 23andMe publicly touted its commitment to data privacy and transparency, in truth, it failed to take reasonable measures to protect its customers’ most sensitive data, ignored known vulnerabilities in its systems, and failed to properly investigate or respond to numerous warnings that its systems had been compromised. The company also misled its customers and the public regarding crucial aspects of the 2023 data breach. In the complaint, filed today in San Francisco Superior Court, Attorney General Bonta alleges 23andMe’s failures to implement and maintain reasonable security procedures and its misleading statements regarding its security and the data breach were unlawful.

“23andMe collected genetic data about millions of people, failed to meet its obligation under California law to keep that information safe, and then lied to consumers about the severity of its 2023 data breach. Our investigation found that the company failed to take basic steps to protect users’ data — data including the sensitive personal information, family histories, and health conditions of consumers,” said Attorney General Bonta. “The sale of this data on the dark web took place amidst a period of mounting anti-Asian American and Pacific Islander and antisemitic hate and violence — and explicitly called attention to the deeply personal and identifying nature of that information. This is disturbing and incredibly dangerous. Today, my office is suing 23andMe for its categorical failure to comply with California law.”  

BACKGROUND

Founded in San Francisco, 23andMe was the first and one of the largest direct-to-consumer genetic testing companies in the world. Customers sent their saliva samples to 23andMe for DNA analysis. The company stored data on consumers’ raw DNA sequence and used that information to provide consumers with reports about their ancestry, ethnicity, and genetic health predispositions. 

On October 6, 2023, 23andMe confirmed that it had suffered a major data breach. Indeed, for five months, a threat actor had breached 23andMe’s systems undetected by accessing about 14,000 customers’ 23andMe accounts. The threat actor leveraged that access, as well as other vulnerabilities within 23andMe’s systems, to obtain the data of nearly 7 million 23andMe customers.

The threat actor used a well-known type of cyberattack called “credential stuffing” that businesses, particularly those that collect and maintain sensitive personal and genetic data, can and should know to guard against. Credential stuffing exploits consumers’ tendency to use weak or common passwords or to reuse log-in credentials by using the same username and password that they use with one company to log into accounts with another company. Here, the threat actor used account credentials stolen in prior data breaches — including the highly publicized breach of MyHeritage, a separate genealogy site that had partnered with 23andMe. Although 23andMe’s data security team was aware of the MyHeritage breach, and 23andMe had encouraged its users to create an account with MyHeritage, 23andMe never checked for or prevented credential reuse, even after the MyHeritage data breach. Once in 23andMe’s systems, the threat actor used a vulnerability involving a critical coding error in “DNA Relatives” — a feature that allowed DNA-related customers to share information and contact each other — to steal additional identifying information, ancestry reports, and reports indicating the percentage of DNA shared with potential relatives about nearly 7 million consumers.

News of 23andMe’s breach came to light after the data of one million consumers were offered for sale on the dark web, specifically touting that the data belonged to Asian American and Pacific Islanders (AAPI) and Jewish users. Disturbingly, this occurred during a period of increasing anti-AAPI and antisemitic hate and violence. 

Even more disturbing, 23andMe’s post-breach statements to consumers were misleading and omitted or misrepresented critical information regarding the breach. While 23andMe assured the public that it had not experienced a data security incident within its systems, downplayed the sensitivity of the stolen data by claiming that the information stolen from the “DNA Relatives” feature was essentially public, and attempted to shift blame for the breach to its customers, 23andMe was simultaneously negotiating and paying a ransom to the threat actor in exchange for, among other things, the threat actor removing damaging information regarding the breach that had been posted online and providing information about multiple 23andMe security vulnerabilities, including vulnerabilities the threat actor exploited during the data breach. 

THE INVESTIGATION & LAWSUIT 

A 2023 investigation by the California Department of Justice and a multistate coalition found that 23andMe’s pre-breach data security procedures and practices fell below security and industry standards in several ways. In fact, 23andMe’s security measures were so lax that the threat actor was able to operate undetected within 23andMe’s systems for over five months, and remarkably, the company only began investigating after the threat actor offered the stolen user data for sale on the dark web and reached out to 23andMe to demand a ransom.

The investigation further found 23andMe: 

  • Failed to implement reasonable security procedures to prevent and detect the well-known risk of credential stuffing.
  • Missed several opportunities to detect the credential stuffing attack.
  • Failed to guard against the exploitation of a coding error in the “DNA Relatives” feature that allowed doctored queries to the 23andMe database.
  • Failed to properly account for genetic data, its nature, and its high-level of sensitivity when drafting and implementing its data security protocols.

Additionally, 23andMe made misleading statements before and after the breach. Before the breach, 23andMe touted its security practices as meeting the highest industry standards. After the breach, 23andMe’s statements omitted key information in an effort to hide and downplay both the breach’s severity and 23andMe’s responsibility for it. 23andMe continued to inform consumers that there was no data security incident within its systems, despite being informed by the threat actor during ransom negotiations of multiple exploitable vulnerabilities within 23andMe’s systems, including vulnerabilities that were used to facilitate the attack.

In the lawsuit, Attorney General Bonta argues that 23andMe failed to implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and genetic data that it maintained to protect that information from unauthorized access. The complaint also alleges that the company made untrue and misleading statements intending to encourage members of the public to use 23andMe’s services or products, including statements regarding its security measures in place at the time of the data breach and the circumstances of the data breach. These failures violated, among other laws, California's Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act.

Today’s lawsuit is separate from the Attorney General’s pending challenge in the U.S. Bankruptcy Court for the Eastern District of Missouri regarding the sale of Californians’ genetic information and material in bankruptcy.