Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.

Case at a glance

Case number
012
Date / range
2020
Sector
Consumer genetics and commercial data
Genetic asset
Genotype kits and law-enforcement matching permissions
Security principle
Consent-State Integrity

Event summary

The 2020 GEDmatch incident demonstrates a rare genetic-security failure: an attack did not merely expose accounts; it temporarily changed effective permissions so profiles that had not opted into law-enforcement matching became searchable for that purpose.

Source: verogen.com — GEDmatch 2020 Permissions Breach source 1.

Source: gedmatch.com — GEDmatch 2020 Permissions Breach source 2.

The case in context

The distinctive failure was a change in the operation of privacy choices. Profiles that were not intended to participate in law-enforcement matching became temporarily searchable for that purpose. That creates an integrity question alongside the confidentiality question: did the system enforce the user's recorded choice?

Temporary searchability is not proof that every profile was viewed or used. A useful incident account separates the changed settings, the period of exposure, and any evidence of actual queries. Restoring a displayed preference is only part of recovery; the authorization paths that apply it also need to be checked.

Acquisition and processing

platform compromise → authorization-state alteration → opted-out profiles become matchable → downstream searches may occur → trust and audit problem

The sequence of events

  1. platform compromise
  2. authorization-state alteration
  3. opted-out profiles become matchable
  4. downstream searches may occur
  5. trust and audit problem

What became inferable or exposed

Genotype kits and law-enforcement matching permissions

The 2020 GEDmatch incident demonstrates a rare genetic-security failure: an attack did not merely expose accounts; it temporarily changed effective permissions so profiles that had not opted into law-enforcement matching became searchable for that purpose.

Security dimensions

Confidentiality

The confidentiality question concerns genotype kits and law-enforcement matching permissions. Exposure and further inference must be distinguished from the fact of collection or availability.

Integrity

The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Consent-State Integrity identifies the particular boundary examined here.

Availability

Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.

Provenance

The relevant chain follows genotype kits and law-enforcement matching permissions through the stages shown below. Missing public detail is not proof that internal records did not exist.

GeneticSecurity.org analysis

Genetic Exposure Radius

Not assessed

No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Persistence Risk

Not assessed

Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Provenance Integrity

Not assessed

A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Proposed classification and its limits

Suggested GER: GER-3. Suggested GPR: GPR-4. Suggested GPI: GPI-2 because system state and access history require reconstruction.

These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.

What this case does not prove

Temporary searchability does not establish that every profile was searched, exported, or used in an investigation.

Mitigations and lessons

  • Tamper-evident consent logs
  • Immutable authorization history
  • Deny-by-default matching
  • Continuous policy-drift detection
  • Privileged-access isolation
  • Incident-specific query auditing
  • Rapid user notice
  • Post-incident proof of restored settings

Primary sources

Secondary sources

No additional source listed. See the evidence notes for limitations.

Policy and standards

Genetic Security Policy and Standards

Review and correction history

Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.

Correction policy and log

Cite this case

GS-CASE-012. GEDmatch 2020: When a Breach Rewrote Consent. GeneticSecurity.org. https://geneticsecurity.org/cases/012-gedmatch-2020-permissions-breach/