Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.

Case at a glance

Case number
013
Date / range
2018
Sector
Consumer genetics and commercial data
Genetic asset
Email addresses and hashed passwords
Security principle
Exposure Classification Accuracy

Event summary

MyHeritage reported that a file containing email addresses and hashed passwords for about 92.3 million accounts was found outside the company, while its DNA and family-tree systems were stored separately and it had no evidence at the time that genetic data had been compromised. The lesson is disciplined breach classification.

Source: blog.myheritage.com — MyHeritage 2018 Breach: A Negative Control source 1.

The case in context

MyHeritage's account of the incident identified email addresses and password hashes while distinguishing its separately stored DNA and family-tree systems. That distinction makes this case a useful counterexample to headlines that treat every breach at a genetics business as a genomic disclosure.

Authentication information can still matter. Compromised credentials may create a path toward other systems, but a possible later account takeover is different from evidence that it happened. The event should be described using the affected data classes in the disclosure, with any further exposure treated as a separate question.

Acquisition and processing

account database exposure → emails/password hashes → credential cracking or reuse risk → possible future account compromise; no confirmed genetic-data exposure in the original disclosure

The sequence of events

  1. account database exposure
  2. emails/password hashes
  3. credential cracking or reuse risk
  4. possible future account compromise; no confirmed genetic-data exposure in the original disclosure

What became inferable or exposed

Email addresses and hashed passwords

MyHeritage reported that a file containing email addresses and hashed passwords for about 92.3 million accounts was found outside the company, while its DNA and family-tree systems were stored separately and it had no evidence at the time that genetic data had been compromised. The lesson is disciplined breach classification.

Security dimensions

Confidentiality

The confidentiality question concerns email addresses and hashed passwords. The documented scope does not establish disclosure of raw genomic data.

Integrity

The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Exposure Classification Accuracy identifies the particular boundary examined here.

Availability

Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.

Provenance

The relevant chain follows email addresses and hashed passwords through the stages shown below. Missing public detail is not proof that internal records did not exist.

GeneticSecurity.org analysis

Genetic Exposure Radius

Not assessed

No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Persistence Risk

Not assessed

Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Genetic Provenance Integrity

Not assessed

A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.

Confidence: not assigned. Classification: GeneticSecurity.org analysis.

Proposed classification and its limits

Suggested GER: GER-0 for the documented incident; note hypothetical GER expansion only as a separate risk. Suggested GPR: GPR-0/1. GPI: not central.

These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.

What this case does not prove

It does not prove that DNA data was stolen. It also does not prove that separation alone makes a genetic platform secure.

Mitigations and lessons

  • Password hashing resistant to offline attack
  • MFA
  • Credential-stuffing defenses
  • Network and data-store separation
  • Breach scoping by data class
  • Evidence-preserving investigation
  • Precise public notices

Primary sources

Secondary sources

No additional source listed. See the evidence notes for limitations.

Policy and standards

Genetic Security Policy and Standards

Review and correction history

Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.

Correction policy and log

Cite this case

GS-CASE-013. MyHeritage 2018: A Breach at a DNA Company Is Not Automatically a DNA Breach. GeneticSecurity.org. https://geneticsecurity.org/cases/013-myheritage-breach-genetic-data-negative-control/