TL;DR: California Attorney General Rob Bonta filed a civil complaint on Thursday, May 28, 2026, against Chrome Holding Co., the post-bankruptcy successor to 23andMe, over the 2023 data breach that exposed the DNA-related data of nearly 7 million people [1]. The complaint alleges 23andMe failed to require password resets or multi-factor authentication after a 2017 MyHeritage credential leak was traced to its users, and that the company let a threat actor operate inside its systems for five months before investigating, then only after the stolen data appeared for sale on the dark web with a ransom demand [1]. About 1.1 million of the affected users were Asian-Pacific Islander and Ashkenazi Jewish, which Bonta's office called out as "disturbing and incredibly dangerous" given the hate and violence targeting both groups in 2023 [1]. The state action lands four months after the federal bankruptcy-court settlement received final approval on January 30, 2026, and while that fund sits waiting for the bankruptcy reconciliation to close [2][3].
The California Lawsuit
Bonta's complaint, filed in California state court, names Chrome Holding Co. as the defendant. Chrome is the corporate name 23andMe Holding Co. and 23andMe, Inc. adopted after the July 14, 2025 closing of the bankruptcy sale to TTAM Research Institute, the nonprofit led by 23andMe co-founder Anne Wojcicki [2][4]. The complaint seeks civil penalties and an injunction blocking further violations of California consumer privacy and data-security law.
The legal theory is the standard state-AG playbook for a 2023 breach: 23andMe knew about credential-stuffing risk from the October 2017 MyHeritage incident, which had been traced to a 23andMe partner and produced a list of credentials that were likely to be reused against 23andMe's own login page. 23andMe did not, the complaint alleges, require affected users to reset passwords or enable multi-factor authentication, both of which the state characterizes as "common protocols" for any consumer-facing service handling health-adjacent personal data [1].
California is the most aggressive state on data-breach enforcement, but it is not the only state. Twenty-seven states and the District of Columbia sued to block the 23andMe bankruptcy sale in June 2025, arguing that the genetic data held by 23andMe would transfer to TTAM without meaningful user consent [5]. That coalition lost in court: a federal bankruptcy judge approved the sale on June 30, 2025 [6]. The California AG's office was not part of that coalition filing, and its new suit does not revisit the sale question. The new suit is forward-looking: it targets the post-sale entity for the pre-sale conduct.
What Happened in 2023
The 2023 breach began with a credential-stuffing attack, the technique of running large lists of username and password pairs harvested from previous breaches against 23andMe's login page until some of them work. The MyHeritage leak of October 2017 had produced exactly that kind of list. Once the attacker had a foothold on 14,000 accounts, the second stage of the attack exploited 23andMe's DNA Relatives feature, which lets users opt in to a relative-finding service that exposes profile and ancestry data to genetic matches. The attacker scraped the profiles of everyone connected to the 14,000 compromised accounts, and that is how 14,000 account takeovers became a breach affecting nearly 7 million people [1][7].
What was exposed, per the original 23andMe breach notification: display names, birth years, self-reported locations, family surnames, grandparents' birthplaces, ethnicity estimates, and in many cases, genetic health information flagged by users [7]. The credential-stuffing vector meant the data was scraped, not posted by the affected users. Many of the 7 million never had a chance to opt out, because their exposure came through a relative who reused a password.
The threat actor was inside 23andMe's environment for five months before the company began investigating, and the investigation started only after the stolen data was offered for sale on the dark web and a ransom demand was delivered, according to the complaint [1]. 23andMe's account at the time was that the credential stuffing was caught quickly. The state's complaint is the first public document to put a five-month timeline on the attacker dwell time.
The dark-web sale listing in October 2023 specifically flagged that about 1.1 million of the affected users were Asian-Pacific Islander and Ashkenazi Jewish, two groups that saw coordinated spikes in hate incidents in 2023. Bonta's press release on the lawsuit tied the data sale to that broader context: "This took place amidst a period of mounting anti-Asian American and Pacific Islander and antisemitic hate and violence. This is disturbing and incredibly dangerous" [1]. The 1.1 million figure is the most concrete public estimate of how the breach mapped onto the targeted ethnic communities.
23andMe's Collapse, in Three Steps
The state lawsuit is a 2026 action against a 2023 breach, and the entity it names is a 2025 entity. To follow the suit, you have to follow the company's path through the bankruptcy estate.
March 2025: 23andMe Holding Co. files for Chapter 11 bankruptcy protection in the U.S. Bankruptcy Court for the Eastern District of Missouri, Case No. 25-40976 [2]. The filing came after a 2023 valuation crash, a 2024 board fight with founder Anne Wojcicki, and the failure of a non-bankruptcy sale process. The class action settlement, originally filed as In re 23andMe, Inc. Customer Data Security Breach Litigation, Case No. 24-md-03098-EMC, in the Northern District of California, was transferred into the bankruptcy court once the Chapter 11 was filed [2].
July 14, 2025: TTAM Research Institute, a nonprofit led by Wojcicki, closed on its purchase of substantially all of 23andMe's assets, including the genetic database, out of the bankruptcy estate. The bankruptcy court entered an order approving the sale on July 27, 2025. After closing, 23andMe Holding Co. and 23andMe, Inc. formally changed their legal names to Chrome Holding Co. and ChromeCo, Inc., respectively, with the litigation and settlement obligations transferring with the entity [2][6].
January 30, 2026: The bankruptcy court entered a Final Approval Order (docket 1875) granting final approval of the data-breach class action settlement [2]. The order authorizes the settlement fund, the settlement benefits plan, and the deficiency cure process. The order also confirms what the Kroll-administered settlement website states plainly: "Settlement payments will not be distributed until the Bankruptcy reconciliation process is resolved, which may take several months or longer" [2]. The June 12, 2026 deadline for filing Deficiency Cure Forms closed yesterday, and the administrator has not announced a distribution timeline.
Two Parallel Tracks, Two Different Payers
What makes the California AG suit interesting is that it runs in parallel to, not in place of, the federal class settlement. The two actions are on different tracks, against different defendants (the class action is now against Chrome Holding Co. and the bankruptcy estate; the AG suit is against Chrome Holding Co. for civil penalties and injunctive relief), with different plaintiffs (the certified settlement class versus the State of California), and they have different outcomes.
The federal class settlement, when its cash finally moves, will compensate the 7 million class members for documented out-of-pocket losses, statutory damages, and five years of Privacy and Medical Shield plus genetic monitoring through Cyberscout. The cash tier is up to $10,000 for extraordinary documented claims, up to $165 for health-information claims, and an estimated $100 in statutory damages for residents of Alaska, California, Illinois, and Oregon [2][8]. The total cash pool has not been publicly disclosed in dollar terms by the Kroll settlement administrator, and The Record's June 12, 2026 report on a $47 million approved fund has not been confirmed by a court filing or by the settlement website as of this writing.
The California AG suit, if successful, would impose civil penalties that are not paid to victims. Under California's Unfair Competition Law (Business and Professions Code section 17200) and the Consumers Legal Remedies Act, civil penalties for data-security violations can run into the thousands of dollars per violation, multiplied across a class of affected California residents. The complaint does not name a specific dollar figure. The injunctive relief is potentially broader: it could require Chrome Holding Co. to implement specific security measures, conduct audits, and report to the AG's office for a defined period.
The two tracks also have different statute-of-limitations pressure. The federal settlement closes the books on most private claims arising from the 2023 breach. The state AG action is a law enforcement action, and it is not foreclosed by the settlement. That is the structural point of state AG data-breach enforcement: the company settles the class action for the class, and the state comes in separately for the public-interest piece.
What This Means
For the 7 million affected class members, the California suit does not change the federal settlement math. It does signal that the state is not treating the bankruptcy transfer as a clean break. Chrome Holding Co. inherited 23andMe's data, 23andMe's customers, and 23andMe's pre-bankruptcy conduct, and the California AG is asserting that the conduct is still actionable. If the state wins an injunction, Chrome will have to run its consumer-facing service under a court-ordered security regime that previous 23andMe was not required to follow.
For the broader consumer DNA industry, the lawsuit continues a pattern. State AGs have been the most consistent enforcer on data-security obligations for direct-to-consumer genetic testing, in part because federal law is thin. HIPAA does not cover direct-to-consumer DNA testing. The Genetic Information Nondiscrimination Act (GINA) blocks employer and health-insurer discrimination, but it does not regulate how the testing company itself handles the data. The Federal Trade Commission has acted against a handful of companies under Section 5 of the FTC Act, but the FTC's data-security enforcement has been weaker under the current commission than under prior leadership. That leaves state AGs as the de facto privacy regulator for the industry, and California's lawsuit is the most concrete 2026 example.
For TTAM Research Institute, the nonprofit that bought the 23andMe assets, the lawsuit is a real but bounded liability. Chrome Holding Co. is the named defendant, not TTAM directly. But Chrome is the corporate successor to the entity TTAM bought, and Chrome's ability to pay a civil penalty is going to depend on the company's post-bankruptcy cash position, which has not been publicly disclosed.
What to Watch in the Next 90 Days
Service of process and Chrome's response. Chrome Holding Co. has not yet filed a public response to the California complaint. The company's first filing will tell us whether it intends to litigate, settle, or default. Given that the entity is the post-bankruptcy successor of a company that has already settled the federal class action, a quick settlement is the more likely path. Watch for an AG press release announcing a stipulated judgment.
Other state AGs. California is the first state AG to file a 2023-breach action against Chrome. The 27-state coalition that sued to block the bankruptcy sale in 2025 is the natural pool of follow-on plaintiffs. If even one more state files, the case shifts from a single-state action to a multi-state enforcement pattern, and that changes Chrome's settlement math significantly.
The federal class settlement distribution. The Kroll-administered settlement website has not announced a distribution timeline. The bankruptcy reconciliation process is the gate, and the bankruptcy court has not signaled when that gate opens. Class members who filed claims in February 2026 are still waiting. The longer the wait, the more credible the prediction that the cash pool will be smaller than the projected $30 to $50 million range the original settlement estimate suggested.
TTAM's data-handling policy. TTAM Research Institute has not published a public-facing security update since the July 2025 closing. A 2026 data-handling policy or a security-incident response plan, if TTAM issues one, will tell us whether the new owner is operating at the level the state AG complaint implies 23andMe was not.
Sources
- Associated Press: California attorney general sues 23andMe over user data breach (May 28, 2026, by Jaimie Ding)
- 23andMe Data Breach Settlement Official Site (Kroll Settlement Administration, court-authorized, U.S. Bankruptcy Court for the Eastern District of Missouri, Case No. 25-40976-357)
- 23andMe Data Settlement Documents page (Final Approval Order dckt 1875 dated January 30, 2026; Settlement Agreement; Addendum dated November 21, 2025; Settlement Benefits Plan; Amended Order Confirming Fifth Amended Chapter 11 Plan dckt 1696)
- NPR: Judge OKs sale of 23andMe to nonprofit led by founder (June 30, 2025)
- NPR: Dozens of states sue to block the sale of 23andMe personal genetic data (June 10, 2025)
- NPR: 23andMe is filing for bankruptcy. Here's what it means for your genetic data (March 24, 2025)
- HIPAA Journal: 6.9 Million 23andMe Users Affected by Data Breach (October 2023, original breach coverage)
- Wikipedia: 23andMe data leak (procedural summary and timeline cross-reference)
Published: June 13, 2026