← Blog

California Sues 23andMe Successor Over 7M Genetic Records

Share on X

On May 30, 2026, California Attorney General Rob Bonta filed suit against Chrome Holding Co.—the corporate debtor name for the genetic-testing business formerly marketed as 23andMe—alleging the company failed to safeguard customer data during the October 2023 intrusion that exposed roughly seven million people, including more than 850,000 Californians. The enforcement action is a reminder that genetic data breaches have decade-long tail risks even after bankruptcy sales and rebranding.

Underlying 2023 incident

The core hack combined credential stuffing against reused passwords with abuse of the DNA Relatives feature, allowing criminals to scrape ancestry and genetic information at scale. 23andMe notified customers in late 2023; our historical record 23me2023 documents roughly 6.9 million affected accounts in earlier regulatory summaries. The May 2026 AG complaint rounds the nationwide impact to nearly seven million and emphasizes categories such as raw genetic data and health reports later offered for sale on criminal markets.

Why the defendant name changed

23andMe filed for bankruptcy in 2024 and was acquired by TTAM Research Institute, a nonprofit led by former CEO Anne Wojcicki. Bonta’s suit targets the post-bankruptcy holding structure because California alleges ongoing obligations to protect legacy customer data—not because a brand-new hack occurred on May 30.

Unique harms of genetic data

  • Immutable identifiers: unlike passwords, you cannot rotate your genome after a leak.
  • Familial exposure: DNA Relatives links expose relatives who never purchased a kit.
  • Insurance and employment discrimination fears even when laws like GINA provide partial protections.
  • Targeted scams referencing ancestry results or health predispositions.

What the AG is seeking

Press releases from the California Attorney General frame the case as protecting consumers whose highly sensitive information was inadequately secured and later monetized by criminals. Expect litigation over retention policies, MFA deployment timelines, and incident disclosure practices rather than a single “patch Tuesday” fix.

Steps for affected customers

  1. Search official AG and company notice sites—not emailed “genetic privacy” links from unknown domains.
  2. Freeze credit and enable fraud alerts; genetic breaches often pair with identity theft.
  3. Be skeptical of phishing referencing “relative match” or “health risk” downloads.
  4. Consult legal counsel if you receive formal notice as a class member; do not pay unsolicited “data removal” brokers.

Researchers and journalists

Distinguish this 2026 lawsuit from fresh 2026 intrusion claims elsewhere in the news cycle. BreachHistory tags the row with 23andme-california-ag-suit2026 and links to the 2023 technical record for forensic context. Follow the 23andMe company page for future settlement or judgment updates.

Policy implications

State AG actions may outlive federal bankruptcy proceedings, shaping how distressed consumer DNA vendors must fund monitoring and deletion programs. Other states may mirror California’s filing, multiplying compliance costs for any acquirer of genetic databases.

Comparison with other health-data enforcement

May 2026 also brought heavy HIPAA disclosures—see our HIPAA roundup—but genetic enforcement raises distinct ethical questions about irreversible data types. Security teams at wellness startups should treat this suit as a benchmark for board-level data-governance investment.

Timeline for consumers

Although the intrusion occurred in 2023, the May 30, 2026 lawsuit is the headline event for Californians receiving fresh media coverage. If you purchased a kit years ago, your data may still be in scope of monitoring offers tied to the underlying breach—not this filing alone. Relatives who never tested but appear in DNA Relatives graphs should also watch for scams.

Technical controls the case will scrutinize

Expect discovery around rate limiting on login endpoints, mandatory MFA rollout dates, DNA Relatives default opt-in settings, and threat-intelligence sharing with law enforcement once dark-web sales were detected. Developers at other genomics startups should pre-emptively document how they would disable high-risk APIs during credential-stuffing spikes.

Dark-web monetization risk

AG statements emphasize that hackers listed genetic material for sale in 2023. Even if current owners assert improved security, previously exfiltrated genotypes cannot be “patched.” Consumers should assume permanent exposure and avoid uploading new raw data to untrusted third parties promising “privacy fixes.”

Why May 30, 2026 matters now

Social posts from policy watchers such as @CalPolicy resurfaced the breach because the lawsuit—not the intrusion—dropped on May 30. Journalists covering Sacramento tech regulation should cite the OAG complaint for precise California victim counts rather than recycled 2023 headlines alone. National reporters can still reference the nearly seven million nationwide figure when discussing genetic privacy legislation in Congress.

Monitoring on BreachHistory

Enable alerts on the 23andMe timeline if you need updates when settlements, fines, or amended complaints publish. We will not inflate victim totals unless a court or regulator attests new numbers.

Canonical record: 23andMe California AG suit 2026. Explore platform tools and why we catalog enforcement actions alongside raw intrusions.

Sources: LA Times, CA OAG