California Sues 23andMe's Successor Over Genetic Data Breach (2026)
Independently fact-checked against primary sources (last audited June 3, 2026). · 4 primary sources cited on this page. How we verify our legal content

California Attorney General Rob Bonta sued Chrome Holding Co., the successor to bankrupt 23andMe, on May 28, 2026, alleging it failed to protect the genetic and personal data of nearly 7 million people in the 2023 breach and misled customers about it. The complaint invokes California's Genetic Information Privacy Act and the CCPA.
Information last verified on June 3, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article addresses a California enforcement action and the California statutes it invokes. It does not state the genetic-privacy law of other states. For your state, see the state data-privacy and data-breach pages.
What Happened
On May 28, 2026, California Attorney General Rob Bonta filed a civil enforcement action, People v. Chrome Holding Co., in San Francisco Superior Court against the San Francisco company now known as Chrome Holding Co., formerly 23andMe. The complaint arises from the company's 2023 data breach. According to the Attorney General, an attacker accessed roughly 14,000 customer accounts, then used the company's opt-in DNA Relatives feature and other weaknesses to reach the profiles of nearly 7 million people, including 855,541 Californians.
The complaint alleges the company failed to take reasonable measures to protect highly sensitive information about customers' health, genetic predispositions, biological relatives, ancestry, and ethnicity. It further alleges the company ignored known vulnerabilities, failed to respond to repeated warnings that its systems had been compromised, and then made untrue or misleading statements about its security and about the circumstances of the breach.
The Attorney General asks the court to impose civil penalties and to enjoin the company from further violations of California's privacy laws. The action follows the company's bankruptcy and rebranding, and it tests whether a successor entity can be held to account for a predecessor's data-security failures. As of June 3, 2026, the company has not answered the complaint and the court has not ruled.

What the Law Actually Says
California regulates consumer DNA-testing companies through the Genetic Information Privacy Act, enacted by SB 41 in 2021 and codified at Civil Code section 56.18 and following. The act requires direct-to-consumer genetic-testing companies to obtain a consumer's express consent for the collection, use, and disclosure of genetic data, and to implement reasonable security to protect it. The complaint pairs that act with the state's Reasonable Data Security Law and with the California Consumer Privacy Act, and following, which the Attorney General and the California Privacy Protection Agency enforce.
The Attorney General also invokes the False Advertising Law and the Unfair Competition Law, the broad statutes California uses to challenge misleading statements and unlawful business practices. Together these laws let the state seek civil penalties per violation and injunctive relief, rather than the individual damages a private class action would pursue.
This action runs alongside private litigation over the same breach. For the consumer-facing framework, see the explainers on California data privacy laws and California data breach notification laws.

Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Two features of this case stand out. First, it is a genetic-data case, and genetic data is permanent. A breached password can be reset; a breached genome cannot. That is the policy reason California enacted the Genetic Information Privacy Act in 2021, and it is why an enforcement action built on that statute carries weight beyond the dollar figures.
Second, the defendant is a successor. By naming Chrome Holding Co. rather than the pre-bankruptcy 23andMe entity, the Attorney General signals that corporate restructuring is not a clean exit from data-security liability. That theory, if it holds, matters well past this company, because data-rich firms routinely change hands. We are not predicting how the court will rule. The allegations are unproven, and successor-liability questions are fact-specific and contested. What the filing establishes is the state's enforcement posture: California is willing to pursue the entity that holds the data, through bankruptcy and a name change.
How This Affects You
If you were a 23andMe customer, the breach at issue dates to 2023, and notification obligations under California law are addressed in the breach-notification explainer. Consumers who want to limit further exposure generally can request deletion of their account data and ask that any stored biological sample be destroyed; genetic-testing companies subject to the Genetic Information Privacy Act must honor valid deletion and revocation requests. This is general information, not a step-by-step instruction for your situation.
More broadly, an enforcement action is not the same as a consumer payout. Civil penalties recovered by the Attorney General go to the state, not to individuals. Consumers seeking individual compensation typically must look to separate private litigation or any approved class settlement, which proceeds on its own schedule and terms.
This is general legal information, not legal advice. It covers a California enforcement action and the California statutes it invokes, verified on June 3, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- California data privacy laws: CCPA and CPRA
- California data breach notification laws
- What is the CCPA?
Last updated: 2026-06-03. This is a developing story; details verified as of June 3, 2026.
Related news
Frequently Asked Questions
Who did California sue over the 23andMe breach?
California Attorney General Rob Bonta sued Chrome Holding Co., the company formerly known as 23andMe, in San Francisco Superior Court on May 28, 2026, in People v. Chrome Holding Co.
How many people were affected by the 2023 23andMe breach?
According to the Attorney General, attackers accessed about 14,000 accounts and then reached data on nearly 7 million people through the opt-in DNA Relatives feature, including 855,541 Californians.
What laws does the complaint say 23andMe violated?
The complaint alleges violations of California's Genetic Information Privacy Act (Civil Code 56.18 et seq.), the Reasonable Data Security Law, the False Advertising Law, the Unfair Competition Law, and the California Consumer Privacy Act.
What is California's Genetic Information Privacy Act?
Enacted by SB 41 in 2021, it requires direct-to-consumer genetic-testing companies to get express consent for collecting, using, and disclosing genetic data and to use reasonable security to protect it.
Can I get money from this lawsuit?
This is a state enforcement action seeking civil penalties and an injunction; penalties go to the state, not to individuals. Individual compensation generally comes through separate private litigation or an approved class settlement, not this case.
Can a company escape data-breach liability by going bankrupt or renaming?
That is one of the questions this case tests. By suing the successor, Chrome Holding Co., California argues a rebrand does not erase liability, but successor-liability questions are fact-specific and the claims here are unproven as of June 3, 2026.
Updates
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.100In forcecited in 11 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinionsMost recently applied by a court: 2026
Leading cases:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Employee Data Privacy: Employer Obligations by State (2026), Privacy Policy Requirements: What You Must Include (2026), Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- California DOJ, Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach (May 28, 2026)(oag.ca.gov).gov
- People v. Chrome Holding Co. fka 23andMe et al., stamped complaint (San Francisco Superior Court)(oag.ca.gov).gov
- California Genetic Information Privacy Act, SB 41 (2021), codified at Cal. Civ. Code Sec. 56.18 et seq.(leginfo.legislature.ca.gov).gov
- California Consumer Privacy Act, Cal. Civ. Code Sec. 1798.100 et seq.(leginfo.legislature.ca.gov).gov
- Fortune, California sues 23andMe over alleged lax data security (May 29, 2026), corroborating coverage(fortune.com)