Skip to content
Data breachResolved

MyHeritage data breach (2017)

Genealogy and DNA-testing service MyHeritage was breached in October 2017, exposing roughly 92 million account email addresses and salted SHA-1 password hashes. The incident was only discovered and disclosed in June 2018.

Victim
MyHeritage
records
92.0M
users
92.0M

In October 2017, the Israeli genealogy and home-DNA-testing service MyHeritage suffered a data breach that exposed roughly 92 million user accounts. Remarkably, the breach went undetected for more than seven months โ€” it only came to light on 4 June 2018, when a security researcher discovered a file named myheritage sitting on a private external server.

What happened

The exfiltrated file contained the email addresses and hashed passwords of every user who had signed up to MyHeritage on or before 26 October 2017 โ€” the date the breach is believed to have occurred. The total came to 91,991,358 accounts. MyHeritage stated that it had no evidence the data was ever used by the attackers, and that it had not seen abnormal activity on user accounts in the interim.

The company was candid that it could not initially determine whether the breach resulted from an external hacker or an insider โ€” for example a malicious employee โ€” and engaged an independent cybersecurity firm to investigate.

Data exposed

Crucially, the breach was limited to credentials:

  • Email addresses
  • Passwords stored as salted SHA-1 hashes โ€” MyHeritage emphasised it never stores plaintext passwords, and that each user's hash uses a different key (salt)

The breach did not expose the service's most sensitive holdings: payment-card data was handled by third-party processors and never stored by MyHeritage, and DNA test results and family-tree data were kept on separate, segregated systems that were not affected. That segregation substantially limited the harm.

Impact and response

MyHeritage disclosed the breach the day after discovering it โ€” an unusually fast turnaround driven in part by the EU GDPR, which had taken effect days earlier (25 May 2018) and mandates breach notification within 72 hours. The company recommended that all users change their passwords, stood up a dedicated incident-response team, and committed to rolling out two-factor authentication.

Because passwords were salted and hashed, the immediate account-takeover risk was lower than in plaintext breaches like VK โ€” but salted SHA-1 is fast to compute, so weak passwords remained crackable, and the email list itself was useful for phishing targeting people interested in genealogy and DNA services.

Why it matters

MyHeritage became an early high-profile test of GDPR-era breach response: rapid disclosure, clear scoping of what was and was not exposed, and visible remediation (2FA, password resets). The incident also highlighted the data-segregation principle done right โ€” by keeping DNA results, family trees and payment data on separate systems, MyHeritage ensured that a credential breach did not become a catastrophic exposure of irreplaceable genetic and genealogical information.

Timeline

  1. The MyHeritage user database is exfiltrated, capturing nearly all accounts created up to that date.

  2. A security researcher finds a file named 'myheritage' on a private external server and notifies MyHeritage.

  3. MyHeritage publicly discloses the breach the day after discovery, citing GDPR notification obligations.

  4. The company convenes an incident-response team, recommends password resets and announces plans for two-factor authentication.

  5. Have I Been Pwned loads 91,991,358 unique MyHeritage accounts.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/MyHeritage
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/myheritage-genealogy-site-announces-mega-breach-affecting-92-million-accounts/
  3. securityweek.comhttps://www.securityweek.com/92-million-user-credentials-lost-myheritage/
  4. vice.comhttps://www.vice.com/en/article/myheritage-hacked-data-breach-92-million/

Related incidents

Data breachResolved

PetFlow data breach (2017)

In December 2017, the pet care delivery service PetFlow suffered a data breach which consequently appeared for sale on a dark web marketplace. Almost 1M accounts were impacted and exposed email addresses and passwords stored as unsalted MD5 hashes.

Victim
PetFlow
Records
990.9K
Data breachResolved

piZap data breach (2017)

In approximately December 2017, the online photo editing site piZap suffered a data breach. The data was later placed up for sale on a dark web marketplace along with a collection of other data breaches in February 2019.

Victim
piZap
Records
41.8M
Data breachResolved

Bukalapak data breach (2017)

In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017. The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes.

Victim
Bukalapak
Records
13.4M