CHL A.I CyberSecurity Scoring
CHL
Company Information
Website:http://www.kermas.com/
Employees number:1
Number of followers:0
NAICS:
Industry Type:Real Estate
Homepage:kermas.com
CHL Risk Score (AI oriented)
Between 600 and 649
CHLReal Estate
Updated:
31/05/2026
31/05/2026
611/1000
Poor
Caa
CHL Global Score (TPRM)
xxxx
CHLReal Estate
Score locked

CHLPoor
Current Score
611Caa (POOR)
01000
4 incidents
-73 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
594
JUNE 2026
587
MAY 2026
684
Breach
27 May 2026 • CHL
Chrome Holding Co.: California sues 23andMe over 7 million genetic profiles exposed in 2023 breach
California Sues 23andMe Over Massive Genetic Data Breach and Security Failures
611
CRITICAL-73
CHR1780223128
California Sues 23andMe Over Massive Genetic Data Breach and Security Failures
California Attorney General Rob Bonta has filed a lawsuit against Chrome Holding Co. (formerly 23andMe Holding Co.) and its subsidiary ChromeCo, Inc. (formerly 23andMe, Inc.), alleging the company failed to protect the genetic data of nearly 7 million customers and misled the public about the severity of a 2023 breach. The complaint, filed on May 27, 2026, in San Francisco Superior Court, details a series of security lapses, a secret ransom payment, and deceptive public statements following one of the most sensitive data breaches in consumer genetics history.
### The Breach: Five Months Undetected
The attack began in late April 2023, when a threat actor used credential stuffing exploiting reused passwords from previous breaches to access 14,000 23andMe accounts. The company had been aware of the 2017 MyHeritage breach, which exposed 92 million credentials, yet failed to cross-check its own customer accounts against known compromised passwords or enforce multi-factor authentication (MFA).
A coding error in 23andMe’s "DNA Relatives" feature allowed the attacker to extract data on 6.9 million users nearly half of its customer base. The breach exposed:
- Raw genetic data, health reports, and self-reported conditions (for 14,000 directly compromised accounts).
- Display names, birth years, ancestry reports, chromosomal data, and family tree links (for 5.5 million users via "DNA Relatives").
- Location data and relationship details (for 1.4 million users via "Family Tree").
Approximately 855,541 affected customers were California residents.
### Missed Warnings and a Secret Ransom
Despite multiple red flags, 23andMe took no action:
- July 6, 2023: The company observed 1.3 million login attempts in a single day from one IP address five times the normal daily volume but did not investigate.
- August 11, 2023: A dark web post advertised stolen 23andMe data, and a Reddit user flagged the sale, but the company closed its investigation after just four days, concluding the data could have been obtained legitimately.
- October 1, 2023: A sample of stolen data including 1.1 million records targeting Ashkenazi Jewish and Asian-Pacific Islander users appeared online during a period of rising hate crimes.
23andMe publicly denied a breach on October 6, 2023, claiming it had "no indication" of a security incident. Meanwhile, the company was privately negotiating with the attacker, ultimately paying a $400,000 ransom in cryptocurrency between October 8–25, 2023. In exchange, the threat actor agreed to destroy the data, disclose vulnerabilities, and provide a cover story though it remains unclear whether the data was actually deleted.
### Security Failures and Legal Consequences
The complaint outlines three major security failures:
1. Failure to prevent credential stuffing – Despite years of industry warnings (including from the FTC, California AG, and CIS), 23andMe did not enforce MFA until November 2023 after the breach had already exposed millions.
2. Coding error in "DNA Relatives" – A flaw allowed attackers to bypass restrictions and extract data on any opted-in user, not just genetic matches.
3. Inadequate data protection policies – The company’s security framework did not specifically address genetic data, despite its permanent and immutable nature.
The lawsuit alleges violations of:
- Genetic Information Privacy Act (GIPA) – $1,000 per violation.
- California Consumer Privacy Act (CCPA) – Up to $7,500 per intentional violation.
- False Advertising Law & Unfair Competition Law – $2,500 per violation.
The Attorney General seeks injunctive relief, civil penalties, and equitable remedies, separate from 23andMe’s ongoing Chapter 11 bankruptcy proceedings.
### Broader Implications
This case highlights California’s aggressive enforcement of privacy laws, particularly for genetic and health data, which cannot be reset like passwords or credit cards. The breach underscores the unique risks of genetic data not just for individuals, but for their biological relatives and the heightened security standards required for companies handling such sensitive information.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
745
MARCH 2026
745
FEBRUARY 2026
744
JANUARY 2026
743
DECEMBER 2025
742
NOVEMBER 2025
742
OCTOBER 2025
741
SEPTEMBER 2025
740
AUGUST 2025
739
OCTOBER 2023
669
Breach
06 Oct 2023 • CHL
Chrome Holding Co.: Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach
California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users
599
CRITICAL-70
CHR1779992999
California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users
California Attorney General Rob Bonta has filed a lawsuit against genetic testing company Chrome Holding Co. (formerly 23andMe), alleging the company failed to protect sensitive customer data and misled the public about a 2023 data breach that compromised nearly 7 million users, including 855,541 Californians. The breach exposed highly personal information, including genetic health predispositions, ancestry details, family histories, and ethnicity data, which was later sold on the dark web.
The attack, which went undetected for five months, began when a threat actor used credential stuffing a method exploiting reused passwords from prior breaches, including a 2021 MyHeritage incident to access 14,000 23andMe accounts. The hacker then exploited a coding vulnerability in the company’s "DNA Relatives" feature, allowing them to scrape data from millions of users. The stolen information was later advertised for sale on the dark web, with sellers explicitly targeting Asian American, Pacific Islander, and Jewish users a particularly alarming detail given the rise in anti-AAPI and antisemitic hate crimes at the time.
Despite 23andMe’s public claims of robust security, the California Department of Justice’s investigation found the company ignored known vulnerabilities, failed to detect the attack for months, and neglected basic safeguards against credential stuffing. Even after the breach was exposed, 23andMe downplayed its severity, falsely asserting that no internal systems were compromised and that the stolen "DNA Relatives" data was effectively public. Meanwhile, the company was secretly negotiating a ransom payment with the hacker, who revealed multiple security flaws during the process.
The lawsuit alleges violations of California’s Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act, citing 23andMe’s failure to implement reasonable security measures and its deceptive statements about the breach. The case is separate from an ongoing bankruptcy dispute over the potential sale of Californians’ genetic data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2023
740
Breach
01 Oct 2023 • CHL
23andMe (Chrome Holding Co.)
23andMe Data Breach (2023)
669
CRITICAL-71
23A4433044101425
In October 2023, 23andMe suffered a massive data breach exposing the personal and genetic data of nearly 7 million users, including highly sensitive DNA profiles, health records, and personally identifiable information (PII). The breach led to severe consequences for affected individuals, including identity theft, targeted harassment (especially against LGBTQ+ members like Salman Jaberi), mental health deterioration (e.g., Elvira Olguín’s vascular episode and vision loss due to stress), and financial fraud. The company filed for bankruptcy in March 2024, facing over 250,000 claims (many suspected fraudulent) tied to the incident, with settlements proposed at $30M–$50M (US) and $3.25M (Canada)—far below the claimed $51 trillion in damages. Victims reported long-term risks, such as nation-state exploitation of immutable DNA data, while the company struggled to verify legitimate claims. The breach’s unique harm—irreplaceable genetic data—heightened distress, with many users feeling the settlements provided insufficient relief for ongoing damages like privacy protection costs, medical expenses, and emotional trauma.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2023
784
Breach
29 Apr 2023 • CHL
23andMe, Inc.
Data Breach at 23andMe, Inc.
735
CRITICAL-49
23A328072725
The California Office of the Attorney General reported a data breach involving 23andMe, Inc. on January 21, 2024. The breach occurred on two dates: April 29, 2023, and September 27, 2023. The breach involved the unauthorized access to personal information of customers, including genetic data and other sensitive information. The incident highlights the vulnerability of genetic testing companies to cyber threats and the potential for significant data leaks.
INCIDENT DETAILS -
TYPE
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CHL ??
What was CHL's A.I Rankiteo Cyber Score in June 2026 ??
What was CHL's A.I Rankiteo Cyber Score in May 2026 ??
What was CHL's A.I Rankiteo Cyber Score in April 2026 ??
What was CHL's A.I Rankiteo Cyber Score in March 2026 ??
What was CHL's A.I Rankiteo Cyber Score in February 2026 ??
What was CHL's A.I Rankiteo Cyber Score in January 2026 ??
What was CHL's A.I Rankiteo Cyber Score in December 2025 ??
What was CHL's A.I Rankiteo Cyber Score in November 2025 ??
What was CHL's A.I Rankiteo Cyber Score in October 2025 ??
What was CHL's A.I Rankiteo Cyber Score in September 2025 ??
What was CHL's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on CHL's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CHL ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CHL's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?