Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 012
- Date / range
- 2020
- Sector
- Consumer genetics and commercial data
- Genetic asset
- Genotype kits and law-enforcement matching permissions
- Security principle
- Consent-State Integrity
Event summary
The 2020 GEDmatch incident demonstrates a rare genetic-security failure: an attack did not merely expose accounts; it temporarily changed effective permissions so profiles that had not opted into law-enforcement matching became searchable for that purpose.
Source: verogen.com — GEDmatch 2020 Permissions Breach source 1.
Source: gedmatch.com — GEDmatch 2020 Permissions Breach source 2.
The case in context
The distinctive failure was a change in the operation of privacy choices. Profiles that were not intended to participate in law-enforcement matching became temporarily searchable for that purpose. That creates an integrity question alongside the confidentiality question: did the system enforce the user's recorded choice?
Temporary searchability is not proof that every profile was viewed or used. A useful incident account separates the changed settings, the period of exposure, and any evidence of actual queries. Restoring a displayed preference is only part of recovery; the authorization paths that apply it also need to be checked.
Acquisition and processing
platform compromise → authorization-state alteration → opted-out profiles become matchable → downstream searches may occur → trust and audit problem
The sequence of events
- platform compromise
- authorization-state alteration
- opted-out profiles become matchable
- downstream searches may occur
- trust and audit problem
What became inferable or exposed
Genotype kits and law-enforcement matching permissions
The 2020 GEDmatch incident demonstrates a rare genetic-security failure: an attack did not merely expose accounts; it temporarily changed effective permissions so profiles that had not opted into law-enforcement matching became searchable for that purpose.
Affected parties and consent
- Direct parties
- GEDmatch users whose matching permissions changed
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns genotype kits and law-enforcement matching permissions. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Consent-State Integrity identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows genotype kits and law-enforcement matching permissions through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality high; integrity critical; availability moderate; provenance moderate; consent critical; persistence high; relational exposure high.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-3. Suggested GPR: GPR-4. Suggested GPI: GPI-2 because system state and access history require reconstruction.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
Temporary searchability does not establish that every profile was searched, exported, or used in an investigation.
Mitigations and lessons
- Tamper-evident consent logs
- Immutable authorization history
- Deny-by-default matching
- Continuous policy-drift detection
- Privileged-access isolation
- Incident-specific query auditing
- Rapid user notice
- Post-incident proof of restored settings
Primary sources
- PRIMARY SOURCE verogen.com — GEDmatch 2020 Permissions Breach source 1
- PRIMARY SOURCE gedmatch.com — GEDmatch 2020 Permissions Breach source 2
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-012. GEDmatch 2020: When a Breach Rewrote Consent. GeneticSecurity.org. https://geneticsecurity.org/cases/012-gedmatch-2020-permissions-breach/