:

CALIFORNIA SUES 23ANDME OVER 7M-PERSON DATA BREACH

AI DESK2 MIN READ
FRI, MAY 29, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

California's attorney general filed suit against genetic testing company 23andMe on Thursday, alleging it failed to adequately protect user data in a 2023 breach affecting approximately 7 million people across the United States.

Attorney General Rob Bonta's lawsuit claims 23andMe neglected to implement reasonable security measures that would have prevented unauthorized access to sensitive genetic and health information. The breach, discovered in 2023, exposed personal data belonging to millions of customers nationwide. The complaint alleges that 23andMe's security failures violated California consumer protection laws. According to Bonta's office, the company failed to use adequate safeguards such as stronger password requirements and additional security protections despite knowing the risks associated with storing genetic data. 23andMe confirmed the breach last year, initially indicating that hackers accessed account information through credential stuffing attacks, where bad actors use previously compromised usernames and passwords to gain entry to accounts. The company subsequently revealed that some users' genetic ancestry data had also been exposed. The lawsuit seeks penalties and damages on behalf of affected California residents. It represents one of several legal challenges the genetic testing company has faced following the breach. The case highlights ongoing tensions between data-intensive tech companies and regulators over security practices. Genetic testing services collect some of the most sensitive personal information available—DNA data that can reveal family relationships, ancestry, and potential health risks. Such information requires heightened protection standards compared to typical consumer data. 23andMe did not immediately respond to requests for comment on the lawsuit. The company has previously stated it takes security seriously and has implemented improvements to its systems following the incident. The litigation underscores regulatory scrutiny of how companies handle biometric and genetic information, particularly in California, where privacy protections have become increasingly stringent in recent years.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

4H AGOIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

4H AGOSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

4H AGOIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

4H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.