惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
ThreatConnect
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
H
Help Net Security
T
Threat Research - Cisco Blogs
Blog — PlanetScale
Blog — PlanetScale
A
Arctic Wolf
G
Google Developers Blog
量子位
U
Unit 42
I
InfoQ
V
V2EX
F
Fox-IT International blog
P
Privacy & Cybersecurity Law Blog
V
Visual Studio Blog
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
C
CERT Recently Published Vulnerability Notes
博客园 - 三生石上(FineUI控件)
T
The Exploit Database - CXSecurity.com
T
Tailwind CSS Blog
SecWiki News
SecWiki News
Know Your Adversary
Know Your Adversary
MyScale Blog
MyScale Blog
宝玉的分享
宝玉的分享
The Hacker News
The Hacker News
Project Zero
Project Zero
Application and Cybersecurity Blog
Application and Cybersecurity Blog
月光博客
月光博客
Recent Commits to openclaw:main
Recent Commits to openclaw:main
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
GRAHAM CLULEY
C
Cisco Blogs
I
Intezer
Simon Willison's Weblog
Simon Willison's Weblog
O
OpenAI News
Recorded Future
Recorded Future
T
Tenable Blog
W
WeLiveSecurity
腾讯CDC
Stack Overflow Blog
Stack Overflow Blog
T
The Blog of Author Tim Ferriss
www.infosecurity-magazine.com
www.infosecurity-magazine.com
D
Docker
C
Cybersecurity and Infrastructure Security Agency CISA
PCI Perspectives
PCI Perspectives

California Attorney General Xavier Becerra - Press Releases

Attorney General Bonta Issues Statement on New State Law That Strengthens Election Safeguards Unlawful, Unconstitutional, and Undemocratic: Attorney General Bonta Stands with D.C. Residents Who Want National Guard Troops Off Their Streets Attorney General Bonta Secures Major Settlement with Predatory Real Estate Company MV Realty, Delivering Relief to Nearly 1,500 Homeowners Attorney General Bonta Opposes Trump Administration’s Attempt to Weaken Discrimination Protections for LGBTQ+ Americans in Federally Funded Programs Don’t Call It Kids’ Safety if Kids Aren’t Safe: Attorney General Bonta Joins Bipartisan Coalition in Opposing KIDS Act Attorney General Bonta Issues Consumer Alert on Price Gouging Following State of Emergency Declaration in Orange County Due to Chemical Incident Attorney General Bonta Announces Arrest of Sacramento Casino Conman Attorney General Bonta Opposes U.S. Department of Education’s Effort to Remove Reporting Requirements That Address Disparities for Students with Disabilities Attorney General Bonta Raises Concerns Over Donor-Advised Fund Restrictions Affecting Southern Poverty Law Center Attorney General Bonta Asks Court to Break Up Live Nation/Ticketmaster Attorney General Bonta Secures Strong Foundation, Settlement in California Concrete Merger California Department of Justice Investigating Tulare County Sheriff’s Department Officer-Involved Shooting Under AB 1506 Time’s Up: Attorney General Bonta Announces Felony Charges Against Southern California Jeweler for $1.5 Million Phantom Rolex Scheme Attorney General Bonta Throws Support Behind Colorado Amid Challenge to Its Social Media Warning Label Law Attorney General Applauds FTC’s Rulemaking on Unfair Food Delivery Fees Harming Consumers Attorney General Bonta Sues Trump Administration Over Attempt to Limit Student Loan Access for Healthcare Workers Time to Pay the Piper: Attorney General Bonta and Governor Newsom Secure Financial Penalties Against Huntington Beach in Housing Lawsuit Attorney General Bonta Opposes Trump Administration’s Proposed Rollback of National Emission Standards for Ethylene Oxide “Cruel, inhumano e inaceptable”: el fiscal general Bonta publica el quinto informe sobre las condiciones en los centros de detención de inmigrantes de California California Department of Justice Releases Proposed "Protecting Our Kids from Social Media Addiction Act (SB 976)” Regulations California Department of Justice Releases Report on Officer-Involved Shooting of Charles Towns Attorney General Bonta Responds to U.S. Supreme Court Decision Preserving Mifepristone Access “Cruel, Inhumane, and Unacceptable”: Attorney General Bonta Releases Fifth Report on Conditions at Immigration Detention Facilities in California Attorney General Bonta Announces Seizure of 8.5 Million Deadly Doses of Fentanyl in Arcadia, Trafficker Arrested Attorney General Bonta Issues Legal Alert to State and Local Agencies: Immigration Status Verification Not a Requirement for HUD Grants Recipients California Department of Justice Investigating San Bernardino County Sheriff’s Department Officer-Involved Shooting Under AB 1506 Attorney General Bonta: Joint Investigation Leads to Felony Charges Against Unlicensed Cannabis Retailer for $7.1 Million in Tax Evasion Attorney General Bonta Seeks Answers from FIFA Regarding Potentially Misleading 2026 World Cup Ticketing Practices Attorney General Bonta Strongly Opposes Trump Administration’s Proposed Rollback of Chemical Accident Prevention Rule Attorney General Bonta Urges FDA to Reverse Guidance Easing Sales of Flavored E-Cigarettes Attorney General Bonta Opposes Another Baseless Attempt by Trump Administration to Access Medical Records on Gender-Affirming Care Attorney General Bonta: Trump Administration's Second Tariff Regime Struck Down as Unlawful Attorney General Bonta Secures End of Unlawful Meat Price Coordination, Announces Settlement with Agri Stats When It Comes to Data Privacy, Consumers Must Be in the Driver’s Seat: Attorney General Bonta, Partners Secure $12.75 Million General Motors Privacy Settlement Attorney General Bonta Opposes Trump Administration’s Attempt to Permanently Exempt Large Logging Projects from Environmental Review Attorney General Bonta Opposes Trump Administration's Proposal to Unlawfully Collect Backup Power Generation Data Attorney General Bonta Protects Critical Homeland Security Funding from Politically Motivated Cut Attorney General Bonta and Secretary of State Weber in Sacramento: Vote Early in June Primary Election and Know Your Voting Rights Attorney General Bonta Applauds DOJ Analyst for Cracking 30-Year-Old Homicide Case, Killer Arrested Attorney General Bonta Rebukes Trump Administration for Proposal to End a Nearly Century-Old Restriction on the Shipping of Handguns Through USPS What’s There to Hide? Attorney General Bonta Urges Transparency in Federal Spending of Taxpayer Dollars Attorney General Bonta Urged U.S. Supreme Court to Protect Telehealth Access to Mifepristone, Welcomes Temporary Halt of Fifth Circuit Ruling Attorney General Bonta Announces Settlement with Aspen Dental Over Corporate Practice of Dentistry and False Advertising Attorney General Bonta Seeks to Halt Trump Administration’s Illegal Greenlight of Oil Transportation in California Pipelines Attorney General Bonta Announces $7.4 Billion Purdue Pharma and Sackler Family Opioid Settlement Now in Effect Attorney General Bonta Welcomes New States and Files Amended Complaint in Nexstar/Tegna Challenge, Lawsuit Now Bipartisan Attorney General Bonta Responds to U.S. Supreme Court Decision in Louisiana v. Callais Attorney General Bonta Co-Leads Bipartisan Effort Urging Credit Card and Payment Processing Companies to Combat Illegal Sales of Tobacco and Nicotine Products Attorney General Bonta Pushes Back on Trump Administration’s Attempt to Undermine Protections for Workers All That Glitters isn’t Gold: Attorney General Bonta Warns Californians of LA 2028 Olympic Games Ticket Scams Attorney General Bonta: Jury Finds Temecula Optometrist Guilty of Felony Sexual Assault of a Minor Attorney General Bonta Opposes Trump Administration Effort to Dismantle Fair Employment Opportunities for Blind Workers Attorney General Bonta Sues Trump Administration Over Failure to Implement Life-Saving Soot Standard Attorney General Bonta Opposes Barriers to Legal Work Authorization for Asylum Seekers Attorney General Bonta Moves to Permanently Block President Trump’s Executive Order Restricting Mail Voting, Exerting Control over Elections Attorney General Bonta Secures Protections Against Forced Reset Trigger Returns in California Following Lawsuit Against Trump Administration Attorney General Bonta: Multi-Jurisdictional Sexual Assault Cold Case Solved, Highlights Importance of Audit of Untested Sexual Assault Evidence Kits Under SB 464 Attorney General Bonta: Card Dealer’s Luck Runs Out, Arrested for Grand Theft Attorney General Bonta Reminds School Districts of Legal Responsibility to Keep All Students Safe by Preventing and Responding to Sexual Harassment, Assault, and Abuse During Graduation Season, Attorney General Bonta and Superintendent Thurmond Issue Updated Guidance on Graduates’ Rights to Wear Tribal Regalia Attorney General Bonta: Despite Trump Administration’s Efforts, Gender-Affirming Care Remains Legal Attorney General Bonta Opposes EPA’s Proposed Emission Standards for Marine Tank Vessel Loading Operations for Failing to Fully Address Health Risks Attorney General Bonta Continues Opposition to Trump Administration’s Mandatory Immigration Detention Without Due Process Attorney General Bonta: California Hits Historic Lows for Gun Violence, Our Work and Investments are Saving Lives but We Stand at a Crossroads Attorney General Bonta Opposes Federal Effort to Strip Housing Support for Mixed-Status Immigrant Households Attorney General Bonta Files Lawsuit Against City of Poway over CEQA Violations Involving the Discovery of Ancestral Remains and Tribal Cultural Resources Attorney General Bonta Secures Important Victory in Lawsuit Challenging HUD Funding Restrictions After Trump Administration Drops Appeal Supporting Healthier Communities: Attorney General Bonta Announces 2026–2027 Tobacco Grant Funding Availability for Local Agencies Naming Names: Attorney General Bonta Secures Public Access to Evidence in Amazon Price Fixing Case Attorney General Bonta Warns Californians About Hidden Risks of Deferred-Interest Medical Credit Cards Attorney General Bonta Opposes Lackluster Consumer Financial Protection Bureau Strategic Plan California Department of Justice Releases Report on Officer-Involved Shooting of John Romero Attorney General Bonta Secures Critical Win in Nexstar/Tegna Merger Challenge, Court Orders Titans to Halt Merging Attorney General Bonta Defends Temporary Protected Status for Immigrants from Somalia Attorney General Bonta Delivers Prime Victory Against Amazon in Ongoing Price Fixing Case Attorney General Bonta Celebrates Historic Verdict in Live Nation/Ticketmaster Trial Attorney General Bonta Co-Leads Bipartisan Coalition in Support of Federal Rule to Increase Transparency in Prescription Drug Pricing Attorney General Bonta, Law Enforcement Partners Announce Armed and Prohibited Persons Arrest in Stockton SB 882 Advisory Council Releases Report and Recommendations on Improving Interactions Between People with Intellectual and Developmental Disabilities and Law Enforcement Too Fast, Too Furious: Attorney General Bonta, California District Attorneys Issue Consumer Alert on E-Bike Safety, Legal Requirements Attorney General Bonta Announces $773 Million Agreement in Principle with Albertsons for its Role in Opioid Epidemic Attorney General Bonta Urges Supreme Court to Preserve Temporary Protected Status for Haitians and Syrians Attorney General Bonta Secures 36-Year State Prison Sentence in Child Sexual Abuse Case Attorney General Bonta Dismantles Los Angeles Hospice Fraud Ring Responsible for $267 Million in Fraud, 21 Charged Attorney General Bonta Leads Multistate Coalition Urging Court to Uphold Constitutional Safeguards Against the Tyranny of the Trump Administration California Department of Justice Investigating San Diego County Sheriff’s Office Officer-Involved Shooting Under AB 1506 Attorney General Bonta Sponsors Legislation Focused on Transparency Around Conditions at Immigration Detention Facilities Attorney General Bonta Opposes U.S. DOJ Exclusive Authority that Shields Federal Attorneys from Accountability Attorney General Bonta Opposes Sable’s Request for Special Permit to Waive Federal Safety Regulation Attorney General Bonta Warns Californians of Investment Scams on Facebook, Instagram, and WhatsApp Attorney General Bonta Opposes Trump Administration Executive Orders Targeting Law Firms’ Rights to Free Speech Attorney General Bonta Co-Leads Lawsuit Challenging President Trump’s Executive Order Restricting Mail Voting, Exerting Federal Control over Elections
Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach
Office of th · 2026-05-28 · via California Attorney General Xavier Becerra - Press Releases

OAKLAND — California Attorney General Rob Bonta today filed a lawsuit against Chrome Holding Co., formerly known as 23andMe, for failing to protect its customers’ sensitive personal information and genetic data related to their health, genetic predispositions and risk factors, biological relatives, ancestry, and ethnicity. In 2023, 23andMe experienced a data breach that affected nearly 7 million users across the United States, including 855,541 Californians. While 23andMe publicly touted its commitment to data privacy and transparency, in truth, it failed to take reasonable measures to protect its customers’ most sensitive data, ignored known vulnerabilities in its systems, and failed to properly investigate or respond to numerous warnings that its systems had been compromised. The company also misled its customers and the public regarding crucial aspects of the 2023 data breach. In the complaint, filed today in San Francisco Superior Court, Attorney General Bonta alleges 23andMe’s failures to implement and maintain reasonable security procedures and its misleading statements regarding its security and the data breach were unlawful.

“23andMe collected genetic data about millions of people, failed to meet its obligation under California law to keep that information safe, and then lied to consumers about the severity of its 2023 data breach. Our investigation found that the company failed to take basic steps to protect users’ data — data including the sensitive personal information, family histories, and health conditions of consumers,” said Attorney General Bonta. “The sale of this data on the dark web took place amidst a period of mounting anti-Asian American and Pacific Islander and antisemitic hate and violence — and explicitly called attention to the deeply personal and identifying nature of that information. This is disturbing and incredibly dangerous. Today, my office is suing 23andMe for its categorical failure to comply with California law.”  

BACKGROUND

Founded in San Francisco, 23andMe was the first and one of the largest direct-to-consumer genetic testing companies in the world. Customers sent their saliva samples to 23andMe for DNA analysis. The company stored data on consumers’ raw DNA sequence and used that information to provide consumers with reports about their ancestry, ethnicity, and genetic health predispositions. 

On October 6, 2023, 23andMe confirmed that it had suffered a major data breach. Indeed, for five months, a threat actor had breached 23andMe’s systems undetected by accessing about 14,000 customers’ 23andMe accounts. The threat actor leveraged that access, as well as other vulnerabilities within 23andMe’s systems, to obtain the data of nearly 7 million 23andMe customers.

The threat actor used a well-known type of cyberattack called “credential stuffing” that businesses, particularly those that collect and maintain sensitive personal and genetic data, can and should know to guard against. Credential stuffing exploits consumers’ tendency to use weak or common passwords or to reuse log-in credentials by using the same username and password that they use with one company to log into accounts with another company. Here, the threat actor used account credentials stolen in prior data breaches — including the highly publicized breach of MyHeritage, a separate genealogy site that had partnered with 23andMe. Although 23andMe’s data security team was aware of the MyHeritage breach, and 23andMe had encouraged its users to create an account with MyHeritage, 23andMe never checked for or prevented credential reuse, even after the MyHeritage data breach. Once in 23andMe’s systems, the threat actor used a vulnerability involving a critical coding error in “DNA Relatives” — a feature that allowed DNA-related customers to share information and contact each other — to steal additional identifying information, ancestry reports, and reports indicating the percentage of DNA shared with potential relatives about nearly 7 million consumers.

News of 23andMe’s breach came to light after the data of one million consumers were offered for sale on the dark web, specifically touting that the data belonged to Asian American and Pacific Islanders (AAPI) and Jewish users. Disturbingly, this occurred during a period of increasing anti-AAPI and antisemitic hate and violence. 

Even more disturbing, 23andMe’s post-breach statements to consumers were misleading and omitted or misrepresented critical information regarding the breach. While 23andMe assured the public that it had not experienced a data security incident within its systems, downplayed the sensitivity of the stolen data by claiming that the information stolen from the “DNA Relatives” feature was essentially public, and attempted to shift blame for the breach to its customers, 23andMe was simultaneously negotiating and paying a ransom to the threat actor in exchange for, among other things, the threat actor removing damaging information regarding the breach that had been posted online and providing information about multiple 23andMe security vulnerabilities, including vulnerabilities the threat actor exploited during the data breach. 

THE INVESTIGATION & LAWSUIT 

A 2023 investigation by the California Department of Justice and a multistate coalition found that 23andMe’s pre-breach data security procedures and practices fell below security and industry standards in several ways. In fact, 23andMe’s security measures were so lax that the threat actor was able to operate undetected within 23andMe’s systems for over five months, and remarkably, the company only began investigating after the threat actor offered the stolen user data for sale on the dark web and reached out to 23andMe to demand a ransom.

The investigation further found 23andMe: 

  • Failed to implement reasonable security procedures to prevent and detect the well-known risk of credential stuffing.
  • Missed several opportunities to detect the credential stuffing attack.
  • Failed to guard against the exploitation of a coding error in the “DNA Relatives” feature that allowed doctored queries to the 23andMe database.
  • Failed to properly account for genetic data, its nature, and its high-level of sensitivity when drafting and implementing its data security protocols.

Additionally, 23andMe made misleading statements before and after the breach. Before the breach, 23andMe touted its security practices as meeting the highest industry standards. After the breach, 23andMe’s statements omitted key information in an effort to hide and downplay both the breach’s severity and 23andMe’s responsibility for it. 23andMe continued to inform consumers that there was no data security incident within its systems, despite being informed by the threat actor during ransom negotiations of multiple exploitable vulnerabilities within 23andMe’s systems, including vulnerabilities that were used to facilitate the attack.

In the lawsuit, Attorney General Bonta argues that 23andMe failed to implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information and genetic data that it maintained to protect that information from unauthorized access. The complaint also alleges that the company made untrue and misleading statements intending to encourage members of the public to use 23andMe’s services or products, including statements regarding its security measures in place at the time of the data breach and the circumstances of the data breach. These failures violated, among other laws, California's Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act.

Today’s lawsuit is separate from the Attorney General’s pending challenge in the U.S. Bankruptcy Court for the Eastern District of Missouri regarding the sale of Californians’ genetic information and material in bankruptcy.