California Attorney General sues 23andMe successor for 2023 data breach

California Attorney General Sues 23andMe Over 2023 Data Breach

SACRAMENTO, CA – California Attorney General Rob Bonta has filed a lawsuit against genetic testing company 23andMe, Inc., alleging the firm failed to adequately protect the personal and highly sensitive genetic information of millions of its users following a significant data breach in late 2023. The legal action, announced on June 18, 2024, underscores growing concerns over data security in an age where companies hold vast troves of personal consumer data, particularly in the health and genomics sector.

The lawsuit stems from a data breach that 23andMe first acknowledged in October 2023. Initially, the company reported that hackers had accessed a limited number of user accounts through "credential stuffing" attacks, where previously compromised login credentials from other sites are used to gain unauthorized access. However, further investigation revealed the breach was far more extensive, with attackers leveraging a "DNA Relatives" feature to access and scrape sensitive personal information and genetic data from millions of users linked to the initial compromised accounts. This included names, birth years, relationship statuses, and, in some cases, genetic ancestry reports.

Attorney General Bonta's complaint alleges that 23andMe was negligent in its security practices, failing to implement reasonable safeguards to protect its vast database of sensitive consumer information. The lawsuit claims the company violated California's Unfair Competition Law and the California Consumer Privacy Act (CCPA) by not providing sufficient data security, failing to properly notify affected customers in a timely manner, and misleading consumers about the robustness of its data protection measures. The state's top legal officer emphasized that companies dealing with such intimate data have a heightened responsibility to ensure its safety.

For consumers, the implications of such a breach are profound. Genetic information, unlike credit card numbers, cannot be changed and can reveal deeply personal details about an individual's health predispositions, ancestry, and family relationships. The exposure of this data not only poses risks of identity theft but also potential discrimination and privacy invasion. Many individuals entrusted 23andMe with their genetic blueprint under the assurance that it would be kept secure, making the breach a significant betrayal of trust.

The lawsuit seeks civil penalties for each violation of California law, which could amount to millions of dollars. Additionally, it aims to compel 23andMe to implement robust, industry-leading security measures to prevent future breaches, provide clear and timely notification to consumers in the event of any security incidents, and conduct regular security assessments. This legal action serves as a stern reminder to all companies handling sensitive consumer data about the critical importance of cybersecurity and the potential legal consequences of neglecting data protection.

This case adds to a growing wave of regulatory scrutiny faced by companies that collect and store sensitive personal information. As genetic testing becomes more commonplace, the ethical and legal frameworks surrounding data ownership and security are continually being tested. The outcome of California's lawsuit against 23andMe could set an important precedent for how genetic data is protected and how companies are held accountable when those protections fail, influencing data security practices across the entire industry.

Original reporting BBC News
Return to Homepage