Forty-two states announced a settlement with 23andMe on July 14 over the 2023 genetic-data breach. California's name is missing from the list, and that is by choice.
Rather than join the multistate agreement, which pays the participating states $18 million now from the company's bankruptcy estate against $150 million in allowed claims, Attorney General Rob Bonta filed California's own lawsuit in May against Chrome Holding Co., 23andMe's post-bankruptcy owner.
Filed in San Francisco Superior Court, the suit seeks civil penalties and alleges the company ignored clear security vulnerabilities and understated how serious the breach was, according to the complaint and news reports. No ruling has been made; the case is ongoing.
The underlying breach compromised the genetic information of 6.9 million customers of the Bay Area-based testing company. Attackers used credential stuffing, recycling passwords stolen from other services, to break into thousands of accounts starting in 2023, then pulled data on millions more users through 23andMe's sharing features.
The company disclosed the breach in October 2023, and some of the stolen data, including names, ancestry information and genetic markers, later surfaced for sale online.
For the states that did settle, the agreement adds security obligations on the company's new custodian: enhanced data-security standards, recurring risk assessments, an independent advisory board and continued data-deletion rights for customers.
