The images in this article were generated with artificial intelligence. How we publish
The lawsuit filed by California Attorney General Rob Bonta against Chrome Holding Co. (formerly 23andMe) marks a key moment in the regulation of genetic privacy: the State accuses the company of not having adequately protected the genetic and personal information of millions of customers, and of offering misleading public communications before and after the incident. The official statement of the prosecution details the allegations and seeks precautionary measures and sanctions; you can see here: California Attorney General's Communiqué.
The facts, as described in the complaint, are already familiar: in October 2023 malicious actors offered for sale a large volume of records and leaked samples to prove their authenticity. The company confirmed that the filtered data were genuine and attributed the intrusion to an attack of credimentary stuffing that exploited weak and reused credentials. However, the prosecution's accusation is not limited to this vector; it also points to a code error in the "DNA Relatives" function and to continuous failures in the detection and response that allowed the exfiltration of approximately 6.9 million customers including 855,541 California residents. The full text of the demand is available here: Application document.

Beyond the numbers, what makes this case particularly sensitive is the nature of the data: genetic information, health preprovisions, ethnicity, and biological relationships that not only identify a person but also affect family members and future generations. Unlike a password or a card number, DNA is immutable; exposure can have persistent effects in terms of discrimination, family privacy and risks of reidentification by third parties that combine public and private sources.
From the technical point of view, the demand points to avoidable failures: lack of effective mitigation against credential stuffing (such as limitation of attempts, detection of bots and brute force, or blocking by abnormal behavior), lack of authentication of multiple factors for sensitive accesses and management of errors and insufficient code tests that left the "DNA Relatives" vulnerable function. These shortcomings highlight a recurring lesson: the prevention of intrusions requires both basic technical controls and continuous governance and external validation.
Legally, the prosecution claims violations of several state regulations, including the California Genetic Information Privacy Act, the California Reasonable Data Security Law and the CCPA, as well as false advertising and unfair competition laws. The application seeks, in addition to corrective measures, the imposition of statutory sanctions which may range from $1,000 and $7,500 for rape which could result in significant amounts if the courts confirm the extent of the violations.
The trade impact was already serious before this demand: administrative investigations, fines in other countries and, according to reports, bankruptcy procedures that even include disputes over the possible sale of genetic databases. The prosecution emphasizes that this conflict over the sale of California data is a separate process, but the very existence of such negotiation increases concerns about the governance of sensitive data in insolvency proceedings.
For users affected or using genetic testing services, practical recommendations are clear: demand transparency and exercise privacy rights. Among the specific actions that a user can take are to request the removal or limitation of the use of its data protected by state laws, change unique and robust passwords, activate authentication of two factors when available, and carefully review any communication on the sale or transfer of data in bankruptcy processes. It is also prudent to consult legal or privacy advice if there is evidence that the data could be marketed without consent.
For companies and product managers in the field of genetics and digital health, the case is a call to raise standards: mandatory implementation of MFA for critical access, anti-bot and Rate-limiting controls, automated testing and safety manuals in functions that handle family links, encryption and data separation, and independent safety audits that include abuse scenarios (adversarial testing). In addition, communication policies must be truthful and proportionate to damage in order to avoid sanctions for misleading advertising.

At the regulatory level, this dispute may set precedents on how the obligation of "reasonable safety" against genetic data is interpreted and what remedies are appropriate when protection fails. Public officials could respond with more prescriptive requirements on minimum controls, stricter reporting obligations and an explicit prohibition on the transfer of genetic data in asset sales without informed and explicit consent.
As the legal process progresses, it is appropriate for the public to keep an eye on two fronts: judicial decisions on liability and sanctions, and movements in bankruptcy proceedings that could attempt to transfer assets that include genetic data. Both fronts will define important limits on sensitive data governance and accountability expectations.
In the end, the lesson is double: data protection is not only a technical exercise but a legal and ethical obligation and the sensitivity of genetic material requires stricter controls and total transparency. Users must actively protect themselves and companies must invest in robust technical controls, safety culture and compliance to prevent incidents like this from recurring.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...