Skip to main content

92 million accounts at DNA testing service MyHeritage have been hacked

DNA testing service MyHeritage said that a third-party security researcher discovered a file on a private server outside MyHeritage’s network that contained email addresses and hashed passwords of everyone who signed up for the service before and on the day of the breach: October 26, 2017. After receiving said file, the company’s Information Security Team verified the content and began an investigation into how someone obtained the information of more than 92 million individuals. 

“MyHeritage does not store user passwords, but rather a one-way hash of each password, in which the hash key differs for each customer,” the company says. “This means that anyone gaining access to the hashed passwords does not have the actual passwords.” 

Recommended Videos

That could be why MyHeritage didn’t find any unusual activity associated with the compromised accounts after the October 2017 breach. The file containing the data simply sat on the external web server untouched by whoever retrieved the data from MyHeritage’s database. With only the email addresses on hand, the perpetrator(s) likely couldn’t break into any accounts. 

Please enable Javascript to view this content

According to MyHeritage, no other information could be obtained by the individual or party responsible for the breach. All payment information resides on third-party services such as PayPal and BlueSnap while family trees and DNA data are stored on a completely separate network and database. So far, there is no evidence that the hacker(s) infiltrated those systems too. 

In addition to forming an internal Information Security Incident Response Team to investigate the breach, MyHeritage also turned to an independent cybersecurity firm for help in determining the extent of the breach, and how to better increase network security to prevent a similar incident in the future. 

Meanwhile, the company plans to expedite development of its upcoming two-factor authentication service. That is an additional security component requiring a second form of identity verification outside the username and password, such as a smartphone for codes sent via SMS messages, fingerprint scanners, facial recognition, or specific apps. The company didn’t say when its two-factor authentication service will go live. 

Despite the hashed passwords found in the leaked data, registered MyHeritage customers are urged to change their passwords as explained here. No other actions are required outside taking advantage of the two-factor service when it eventually goes live.  

“As always, your privacy and the security of your data are our highest priority,” the company says. “We continually assess our procedures and policies and seek new ways to improve our approach to security. We understand the importance of our role as custodians of your information and work every day to earn your trust.” 

The breach went unnoticed until 1 p.m. EST on June 4, 2018 when the security researcher contacted MyHeritage. That means the data sat unused on the external web server for around seven months, giving the hacker(s) plenty of time to infiltrate accounts and gather additional data. But all that effort to infiltrate MyHeritage produced a long list of over 92 million email addresses. 

“We are taking steps to inform relevant authorities as per the General Data Protection Regulation,” the Israel-based company states. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Nvidia celebrates Trump, slams Biden for putting AI in jeopardy
The Nvidia RTX 5090 GPU.

In response to new export restrictions placed on AI GPUs, Nvidia posted a scathing blog criticizing the outgoing Biden-Harris administration. The administration's Interim Final Rule on Artificial Intelligence Diffusion largely targets China with restrictions on AI GPUs, according to Newsweek.

Nvidia disagrees. "While cloaked in the guise of an 'anti-China' measure, these rules would do nothing to enhance U.S. security. The new rules would control technology worldwide, including technology that is already widely available in mainstream gaming PCs and consumer hardware. Rather than mitigate any threat, the new Biden rules would only weaken America’s global competitiveness, undermining the innovation that has kept the U.S. ahead," wrote Nvidia's vice president of government of affairs Ned Finkle.

Read more
This new DirectX feature could completely change how PC games work
A scene from Fortnite running in Unreal Engine 5.

Microsoft has announced that neural rendering capabilities are coming to DirectX soon. Cooperative vector support, as it's called, will lead to "cross-platform enablement of neural rendering techniques," according to Microsoft, and it will usher in "a new paradigm in 3D graphics programming."

It sounds buzzy, but that's not without reason. This past week, Nvidia announced its new range of RTX 50-series graphics cards, and along with them, it revealed a slate of neural rendering features. Neural shaders, as Nvidia calls them, allow developers to execute small neural networks from shader code, running them on the dedicated AI hardware available on Nvidia, AMD, Intel, and Qualcomm GPUs. Microsoft is saying that it will enable these features on all GPUs, not just those sold by Nvidia, through the DirectX API.

Read more
This gaming PC with an RTX 4060 is on sale for $1,000 today
The iBuyPower Trace 7 on a white background.

Best Buy often has some great gaming PC deals, with one highlight available today: Right now, you can buy the iBuyPower Trace 7 gaming PC for $1,000 instead of $1,300. The PC includes the RTX 4060 GPU, so it’s ideal for mid-range gaming. It even comes with a keyboard and mouse, so you only need to make sure you have a screen to add to it. If you’re looking to upgrade your gaming PC for less, here’s what it has to offer.

Why you should buy the iBuyPower Trace 7
You won’t see anything from iBuyPower in our look at the best gaming PCs, but don’t let that discourage you. This is still a good option for those on a budget. This particular model has great hardware for the price. It has an AMD Ryzen 7 5700 CPU teamed up with 16GB of RAM and 1TB of SSD storage. More pivotal for a gaming PC is its graphics card: a GeForce RTX 4060 with 8GB of VRAM.

Read more