Evidence: officially disclosed. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 050
- Date / range
- 2019
- Sector
- Consumer genetics and commercial data
- Genetic asset
- Customer-facing portal information
- Security principle
- Interface Exposure Must Be Scoped by Data Class
Event summary
Veritas Genetics confirmed unauthorized access to a customer-facing portal in 2019 while stating that the portal did not contain genetic data, DNA-test results, or health records. Like MyHeritage, it is a precision test for breach reporting.
Source: techcrunch.com — Veritas Genetics Portal Incident source 1.
The case in context
Veritas stated that the compromised customer-facing portal did not contain genetic data, test results, or health records. The distinction is central to the case, rather than a minor qualification at the end of a breach headline.
Customer support, billing, laboratory, and sequence-storage systems should be mapped separately. Their connections can create additional risk, but that does not prove movement between them occurred in a particular event. The case complements MyHeritage by showing why the interface reached and the information it held deserve their own description.
Acquisition and processing
customer portal compromise → limited account/customer information → investigation and notification; no confirmed genomic store access in the company's statement
The sequence of events
- customer portal compromise
- limited account/customer information
- investigation and notification; no confirmed genomic store access in the company's statement
What became inferable or exposed
Customer-facing portal information
Veritas Genetics confirmed unauthorized access to a customer-facing portal in 2019 while stating that the portal did not contain genetic data, DNA-test results, or health records. Like MyHeritage, it is a precision test for breach reporting.
Affected parties and consent
- Direct parties
- Users affected by the portal incident
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns customer-facing portal information. The documented scope does not establish disclosure of raw genomic data.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Interface Exposure Must Be Scoped by Data Class identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows customer-facing portal information through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality depends on confirmed fields; genetic integrity/availability not established; credential persistence remediable.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-0. Suggested GPR: GPR-0/1 absent genetic data. GPI: not central.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
It does not prove genetic records were exposed, nor that excluding them from one portal resolves every architectural risk.
Mitigations and lessons
- System/data mapping
- Separate trust zones
- MFA
- Precise breach notices
- Evidence preservation
- Portal minimization
- Testing lateral movement paths
Primary sources
No additional source listed. See the evidence notes for limitations.
Secondary sources
- SECONDARY SOURCE techcrunch.com — Veritas Genetics Portal Incident source 1
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-050. Veritas Genetics: Breached Portal, Reportedly No Genetic Results. GeneticSecurity.org. https://geneticsecurity.org/cases/050-veritas-genetics-portal-incident/