California Attorney General Rob Bonta has sued 23andMe over its 2023 breach, alleging the DNA testing company failed to implement reasonable safeguards for highly sensitive customer data and misled consumers about the incident. State investigators said attackers used a credential-stuffing campaign against roughly 14,000 accounts over about five months, ultimately exposing the personal and genetic information of 6.9 million people, including 855,541 California residents. The compromised data reportedly included genetic predispositions, health risk factors, ancestry, ethnicity, and biological-relative information.
The complaint alleges 23andMe failed to defend against a well-known attack technique, overlooked warning signs such as spikes in login attempts and public discussion of the breach, and left additional weaknesses in its DNA Relatives feature. Bonta also said the stolen data was later advertised for sale on the dark web with references to Asian American Pacific Islander and Jewish users, heightening concerns about targeted harm. The lawsuit follows a class-action settlement approved in January 2026 for up to $50 million, and comes as California separately challenges the sale of consumers’ genetic data and biological samples in 23andMe’s bankruptcy case.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
A class action settlement over the breach, previously increased from an initial $30 million agreement to as much as $50 million, received final judicial approval in January 2026.
California Attorney General Rob Bonta filed suit against 23andMe, alleging violations of California privacy, data security, and consumer protection laws tied to the 2023 breach. The complaint says the company failed to implement reasonable protections and misled consumers about the severity and nature of the incident.
After the breach, threat actors sold the stolen 23andMe data on the dark web. The data was advertised as including information on Asian American Pacific Islander and Jewish users, heightening concerns about targeted harm.
In 2023, attackers used credential stuffing to gain unauthorized access to about 14,000 23andMe accounts over roughly five months. Through the company's DNA Relatives feature, the incident exposed personal and genetic information affecting about 6.9 million people, including 855,541 California residents.
The UK Information Commissioner's Office fined 23andMe £2.31 million for failing to protect UK users' genetic data in connection with the 2023 breach. This adds a separate UK regulatory enforcement action beyond the previously documented California lawsuit and class action settlement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
14 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcescworld.com
Open sourcehipaajournal.com
Open sourceblog.23andme.com
Open sourceico-newsroom.prgloo.com
Open sourceoag.ca.gov
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.