California sues 23andMe over alleged ‘lax’ data security that failed to protect nearly 7 million users’ data in 2023 breach
California's attorney general has filed a lawsuit against 23andMe for failing to protect user data in a significant 2023 breach. The breach affected nearly 7 million users and involved the theft of sensitive genetic information. The lawsuit seeks civil penalties and injunctions to prevent further violations of privacy laws.
- ▪The lawsuit alleges that 23andMe's security measures were inadequate, allowing a threat actor to operate undetected for over five months.
- ▪The breach involved the use of stolen user credentials from a previous data breach affecting MyHeritage.
- ▪23andMe has faced criticism for misleading consumers about the severity of the breach and failing to investigate early warning signs.
10 outlets in our directory ran this story, first to last over 21 hours. Coverage spans 2 points on the political spectrum — 1 lean left, 8 centre.
- ▪ 23andMe inherits lawsuit over 'disturbing' DNA data breach — The Register
- ▪ California is suing 23andMe over its 2023 breach that exposed 7 million users' DNA data — Quartz
- ▪ California sues 23andMe over 2023 data breach that affected 7 million users — Engadget
- ▪ California sues 23andMe, alleging it failed to protect user data in 2023 breach — The Hindu — Top
- ▪ California Attorney General sues 23andMe successor for 2023 data breach — Bbc
- ▪ 23andMe Sued by California Over Massive 2023 Data Breach — CNET — News
- ▪ California sues 23andMe over large 2023 data breach — Hacker News (Newest)
- ▪ California AG Rob Bonta sues 23andMe, alleging it failed to protect sensitive user data in a 2023 breach that affected ~7M people across the US (Jaimie Ding/Associated Press) — Techmeme
- ▪ California sues 23andMe over large 2023 data breach — Investing.com — News
Fortune files mainly under business. We currently carry 644 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Fortune |
| Canonical URL | https://fortune.com/2026/05/29/california-sues-23andme-alleged-lax-data-security/ |
| Publication time | Fri, 29 May 2026 13:30:30 +0000 |
| Retrieval time | 2026-05-29T13:45:00.592Z |
| Last seen | 2026-05-29T13:45:00.592Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | dinMTf77Y-WT · 10 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
California’s attorney general sued the genetic testing company formerly known as 23andMe on Thursday, alleging it failed to protect sensitive user data in a 2023 breach that affected nearly 7 million people across the country.Recommended Video Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March. 23andme is known for its direct-to-consumer DNA test kits that provided customers information on their ancestry and genetic predispositions for certain health conditions. The lawsuit calls for various civil penalties against 23andMe and injunctions blocking the company from further violations of California’s privacy protection laws.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Fortune.