Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 013
- Date / range
- 2018
- Sector
- Consumer genetics and commercial data
- Genetic asset
- Email addresses and hashed passwords
- Security principle
- Exposure Classification Accuracy
Event summary
MyHeritage reported that a file containing email addresses and hashed passwords for about 92.3 million accounts was found outside the company, while its DNA and family-tree systems were stored separately and it had no evidence at the time that genetic data had been compromised. The lesson is disciplined breach classification.
Source: blog.myheritage.com — MyHeritage 2018 Breach: A Negative Control source 1.
The case in context
MyHeritage's account of the incident identified email addresses and password hashes while distinguishing its separately stored DNA and family-tree systems. That distinction makes this case a useful counterexample to headlines that treat every breach at a genetics business as a genomic disclosure.
Authentication information can still matter. Compromised credentials may create a path toward other systems, but a possible later account takeover is different from evidence that it happened. The event should be described using the affected data classes in the disclosure, with any further exposure treated as a separate question.
Acquisition and processing
account database exposure → emails/password hashes → credential cracking or reuse risk → possible future account compromise; no confirmed genetic-data exposure in the original disclosure
The sequence of events
- account database exposure
- emails/password hashes
- credential cracking or reuse risk
- possible future account compromise; no confirmed genetic-data exposure in the original disclosure
What became inferable or exposed
Email addresses and hashed passwords
MyHeritage reported that a file containing email addresses and hashed passwords for about 92.3 million accounts was found outside the company, while its DNA and family-tree systems were stored separately and it had no evidence at the time that genetic data had been compromised. The lesson is disciplined breach classification.
Affected parties and consent
- Direct parties
- Account holders described in the MyHeritage notice
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns email addresses and hashed passwords. The documented scope does not establish disclosure of raw genomic data.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Exposure Classification Accuracy identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows email addresses and hashed passwords through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality moderate; integrity low; availability low; consent indirect; persistence of credentials is remediable; genetic persistence not triggered without genetic data.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-0 for the documented incident; note hypothetical GER expansion only as a separate risk. Suggested GPR: GPR-0/1. GPI: not central.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
It does not prove that DNA data was stolen. It also does not prove that separation alone makes a genetic platform secure.
Mitigations and lessons
- Password hashing resistant to offline attack
- MFA
- Credential-stuffing defenses
- Network and data-store separation
- Breach scoping by data class
- Evidence-preserving investigation
- Precise public notices
Primary sources
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-013. MyHeritage 2018: A Breach at a DNA Company Is Not Automatically a DNA Breach. GeneticSecurity.org. https://geneticsecurity.org/cases/013-myheritage-breach-genetic-data-negative-control/