Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Chrome Holdings Ltd.

Chrome Holdings Ltd. Vendor Cyber Rating & Cyber Score

kermas.com

Kermas Limited is an international investment corporation, which operates its own assets through a range of daughter companies.Kermas operates in 11 countries and has a truly global vision, working in a range of diverse sectors. We are committed to seeking out growth opportunities across the world.


CHL A.I CyberSecurity Scoring

CHL
Company Information
Website:http://www.kermas.com/
Employees number:1
Number of followers:0
NAICS:
Industry Type:Real Estate
Homepage:kermas.com
CHL Risk Score (AI oriented)
Between 600 and 649
logo
CHLReal Estate
Updated:
31/05/2026
611/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CHL Global Score (TPRM)
xxxx
logo
CHLReal Estate
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CHL
CHLPoor
Current Score
611Caa (POOR)
01000
4 incidents
-73 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
594Before Incident
JUNE 2026
587Before Incident
MAY 2026
684Before Incident
Breach
27 May 2026CHL
Chrome Holding Co.: California sues 23andMe over 7 million genetic profiles exposed in 2023 breach

California Sues 23andMe Over Massive Genetic Data Breach and Security Failures

611After Incident
CRITICAL-73
CHR1780223128
California Sues 23andMe Over Massive Genetic Data Breach and Security Failures California Attorney General Rob Bonta has filed a lawsuit against Chrome Holding Co. (formerly 23andMe Holding Co.) and its subsidiary ChromeCo, Inc. (formerly 23andMe, Inc.), alleging the company failed to protect the genetic data of nearly 7 million customers and misled the public about the severity of a 2023 breach. The complaint, filed on May 27, 2026, in San Francisco Superior Court, details a series of security lapses, a secret ransom payment, and deceptive public statements following one of the most sensitive data breaches in consumer genetics history. ### The Breach: Five Months Undetected The attack began in late April 2023, when a threat actor used credential stuffing exploiting reused passwords from previous breaches to access 14,000 23andMe accounts. The company had been aware of the 2017 MyHeritage breach, which exposed 92 million credentials, yet failed to cross-check its own customer accounts against known compromised passwords or enforce multi-factor authentication (MFA). A coding error in 23andMe’s "DNA Relatives" feature allowed the attacker to extract data on 6.9 million users nearly half of its customer base. The breach exposed: - Raw genetic data, health reports, and self-reported conditions (for 14,000 directly compromised accounts). - Display names, birth years, ancestry reports, chromosomal data, and family tree links (for 5.5 million users via "DNA Relatives"). - Location data and relationship details (for 1.4 million users via "Family Tree"). Approximately 855,541 affected customers were California residents. ### Missed Warnings and a Secret Ransom Despite multiple red flags, 23andMe took no action: - July 6, 2023: The company observed 1.3 million login attempts in a single day from one IP address five times the normal daily volume but did not investigate. - August 11, 2023: A dark web post advertised stolen 23andMe data, and a Reddit user flagged the sale, but the company closed its investigation after just four days, concluding the data could have been obtained legitimately. - October 1, 2023: A sample of stolen data including 1.1 million records targeting Ashkenazi Jewish and Asian-Pacific Islander users appeared online during a period of rising hate crimes. 23andMe publicly denied a breach on October 6, 2023, claiming it had "no indication" of a security incident. Meanwhile, the company was privately negotiating with the attacker, ultimately paying a $400,000 ransom in cryptocurrency between October 8–25, 2023. In exchange, the threat actor agreed to destroy the data, disclose vulnerabilities, and provide a cover story though it remains unclear whether the data was actually deleted. ### Security Failures and Legal Consequences The complaint outlines three major security failures: 1. Failure to prevent credential stuffing – Despite years of industry warnings (including from the FTC, California AG, and CIS), 23andMe did not enforce MFA until November 2023 after the breach had already exposed millions. 2. Coding error in "DNA Relatives" – A flaw allowed attackers to bypass restrictions and extract data on any opted-in user, not just genetic matches. 3. Inadequate data protection policies – The company’s security framework did not specifically address genetic data, despite its permanent and immutable nature. The lawsuit alleges violations of: - Genetic Information Privacy Act (GIPA) – $1,000 per violation. - California Consumer Privacy Act (CCPA) – Up to $7,500 per intentional violation. - False Advertising Law & Unfair Competition Law – $2,500 per violation. The Attorney General seeks injunctive relief, civil penalties, and equitable remedies, separate from 23andMe’s ongoing Chapter 11 bankruptcy proceedings. ### Broader Implications This case highlights California’s aggressive enforcement of privacy laws, particularly for genetic and health data, which cannot be reset like passwords or credit cards. The breach underscores the unique risks of genetic data not just for individuals, but for their biological relatives and the heightened security standards required for companies handling such sensitive information.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data ExfiltrationFinancial Gain (Ransom)
IMPACT
Financial Loss: $400,000 (ransom paid)23andMe customer databaseDNA Relatives featureFamily Tree featureOperational Impact: Investigation and remediation efforts, enforcement of MFA post-breachBrand Reputation Impact: Significant (misleading public statements, delayed disclosure)Violations of GIPA, CCPA, False Advertising Law, Unfair Competition LawIdentity Theft Risk: High (genetic data, PII, health information)
DATA BREACH
Raw genetic dataHealth reportsSelf-reported conditionsAncestry reportsChromosomal dataFamily tree linksDisplay namesBirth yearsLocation dataRelationship detailsNumber Of Records Exposed: 6.9 million users (1.1 million records advertised on dark web)Sensitivity Of Data: High (genetic and health data)
APRIL 2026
745Before Incident
MARCH 2026
745Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
743Before Incident
DECEMBER 2025
742Before Incident
NOVEMBER 2025
742Before Incident
OCTOBER 2025
741Before Incident
SEPTEMBER 2025
740Before Incident
AUGUST 2025
739Before Incident
OCTOBER 2023
669Before Incident
Breach
06 Oct 2023CHL
Chrome Holding Co.: Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach

California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users

599After Incident
CRITICAL-70
CHR1779992999
California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users California Attorney General Rob Bonta has filed a lawsuit against genetic testing company Chrome Holding Co. (formerly 23andMe), alleging the company failed to protect sensitive customer data and misled the public about a 2023 data breach that compromised nearly 7 million users, including 855,541 Californians. The breach exposed highly personal information, including genetic health predispositions, ancestry details, family histories, and ethnicity data, which was later sold on the dark web. The attack, which went undetected for five months, began when a threat actor used credential stuffing a method exploiting reused passwords from prior breaches, including a 2021 MyHeritage incident to access 14,000 23andMe accounts. The hacker then exploited a coding vulnerability in the company’s "DNA Relatives" feature, allowing them to scrape data from millions of users. The stolen information was later advertised for sale on the dark web, with sellers explicitly targeting Asian American, Pacific Islander, and Jewish users a particularly alarming detail given the rise in anti-AAPI and antisemitic hate crimes at the time. Despite 23andMe’s public claims of robust security, the California Department of Justice’s investigation found the company ignored known vulnerabilities, failed to detect the attack for months, and neglected basic safeguards against credential stuffing. Even after the breach was exposed, 23andMe downplayed its severity, falsely asserting that no internal systems were compromised and that the stolen "DNA Relatives" data was effectively public. Meanwhile, the company was secretly negotiating a ransom payment with the hacker, who revealed multiple security flaws during the process. The lawsuit alleges violations of California’s Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act, citing 23andMe’s failure to implement reasonable security measures and its deceptive statements about the breach. The case is separate from an ongoing bankruptcy dispute over the potential sale of Californians’ genetic data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data exfiltration and sale on dark web
IMPACT
Data Compromised: Genetic health predispositions, ancestry details, family histories, ethnicity data, personally identifiable informationBrand Reputation Impact: Significant (allegations of deceptive statements and security failures)Legal Liabilities: Violations of California’s Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and California Consumer Privacy ActIdentity Theft Risk: High (genetic and personal data exposed)
DATA BREACH
Genetic health predispositionsAncestry detailsFamily historiesEthnicity dataPersonally identifiable informationNumber Of Records Exposed: 7,000,000Sensitivity Of Data: High (genetic and personal data)
OCTOBER 2023
740Before Incident
Breach
01 Oct 2023CHL
23andMe (Chrome Holding Co.)

23andMe Data Breach (2023)

669After Incident
CRITICAL-71
23A4433044101425
In October 2023, 23andMe suffered a massive data breach exposing the personal and genetic data of nearly 7 million users, including highly sensitive DNA profiles, health records, and personally identifiable information (PII). The breach led to severe consequences for affected individuals, including identity theft, targeted harassment (especially against LGBTQ+ members like Salman Jaberi), mental health deterioration (e.g., Elvira Olguín’s vascular episode and vision loss due to stress), and financial fraud. The company filed for bankruptcy in March 2024, facing over 250,000 claims (many suspected fraudulent) tied to the incident, with settlements proposed at $30M–$50M (US) and $3.25M (Canada)—far below the claimed $51 trillion in damages. Victims reported long-term risks, such as nation-state exploitation of immutable DNA data, while the company struggled to verify legitimate claims. The breach’s unique harm—irreplaceable genetic data—heightened distress, with many users feeling the settlements provided insufficient relief for ongoing damages like privacy protection costs, medical expenses, and emotional trauma.
INCIDENT DETAILS -
TYPE
Data BreachPrivacy Violation
IMPACT
Settlement Fund Us: $30 million to $50 millionSettlement Fund Canada: $3.25 million (CA$4.49 million)Individual Claims: Up to $165 (US health data exposed), $100 (statutory payments for certain states), additional payments for extraordinary lossesCompany Asset Sale: $300 million (June 2024)Total Claims Value: $51 trillion (disputed, includes potential fraudulent claims)Personal InformationGenetic/DNA DataHealth DataFamily NamesCredit Information (linked to identity theft)Bankruptcy filing (March 2024)Reputation damageLegal and regulatory scrutinyCustomer trust erosionConfusion over bankruptcy hearingsFear of identity theftMental health impacts (e.g., Elvira Olguín's vascular episode)Harassment and targeted ads (e.g., Salman Jaberi)Brand Reputation Impact: Severe (linked to immutable genetic data exposure and bankruptcy)Class-action lawsuits (US and Canada)Potential fraudulent claims disputesState privacy law violationsRegulatory fines (pending)Identity Theft Risk: High (reported cases like Salman Jaberi's credit report spikes and targeted scams)
DATA BREACH
Genetic/DNA DataPersonal Identifiable Information (PII)Health DataFamily RelationshipsCredit-Linked DataNumber Of Records Exposed: ~7 millionSensitivity Of Data: Extreme (immutable genetic data, health records, family ties)Data Exfiltration: Confirmed (sold or leaked, suspected dark web activity)NamesEmail AddressesGenetic ProfilesFamily ConnectionsHealth Research Data
APRIL 2023
784Before Incident
Breach
29 Apr 2023CHL
23andMe, Inc.

Data Breach at 23andMe, Inc.

735After Incident
CRITICAL-49
23A328072725
The California Office of the Attorney General reported a data breach involving 23andMe, Inc. on January 21, 2024. The breach occurred on two dates: April 29, 2023, and September 27, 2023. The breach involved the unauthorized access to personal information of customers, including genetic data and other sensitive information. The incident highlights the vulnerability of genetic testing companies to cyber threats and the potential for significant data leaks.
INCIDENT DETAILS -
TYPE
Data Breach

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CHL ?
?
What was CHL's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CHL's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CHL's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CHL's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CHL's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CHL's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CHL's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CHL's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CHL's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CHL's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CHL's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on CHL's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CHL ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CHL's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?