MyHeritage data breach (2017)
Genealogy and DNA-testing service MyHeritage was breached in October 2017, exposing roughly 92 million account email addresses and salted SHA-1 password hashes. The incident was only discovered and disclosed in June 2018.
- Victim
- MyHeritage
- records
- 92.0M
- users
- 92.0M
In October 2017, the Israeli genealogy and home-DNA-testing service MyHeritage suffered a data breach that exposed roughly 92 million user accounts. Remarkably, the breach went undetected for more than seven months โ it only came to light on 4 June 2018, when a security researcher discovered a file named myheritage sitting on a private external server.
What happened
The exfiltrated file contained the email addresses and hashed passwords of every user who had signed up to MyHeritage on or before 26 October 2017 โ the date the breach is believed to have occurred. The total came to 91,991,358 accounts. MyHeritage stated that it had no evidence the data was ever used by the attackers, and that it had not seen abnormal activity on user accounts in the interim.
The company was candid that it could not initially determine whether the breach resulted from an external hacker or an insider โ for example a malicious employee โ and engaged an independent cybersecurity firm to investigate.
Data exposed
Crucially, the breach was limited to credentials:
- Email addresses
- Passwords stored as salted SHA-1 hashes โ MyHeritage emphasised it never stores plaintext passwords, and that each user's hash uses a different key (salt)
The breach did not expose the service's most sensitive holdings: payment-card data was handled by third-party processors and never stored by MyHeritage, and DNA test results and family-tree data were kept on separate, segregated systems that were not affected. That segregation substantially limited the harm.
Impact and response
MyHeritage disclosed the breach the day after discovering it โ an unusually fast turnaround driven in part by the EU GDPR, which had taken effect days earlier (25 May 2018) and mandates breach notification within 72 hours. The company recommended that all users change their passwords, stood up a dedicated incident-response team, and committed to rolling out two-factor authentication.
Because passwords were salted and hashed, the immediate account-takeover risk was lower than in plaintext breaches like VK โ but salted SHA-1 is fast to compute, so weak passwords remained crackable, and the email list itself was useful for phishing targeting people interested in genealogy and DNA services.
Why it matters
MyHeritage became an early high-profile test of GDPR-era breach response: rapid disclosure, clear scoping of what was and was not exposed, and visible remediation (2FA, password resets). The incident also highlighted the data-segregation principle done right โ by keeping DNA results, family trees and payment data on separate systems, MyHeritage ensured that a credential breach did not become a catastrophic exposure of irreplaceable genetic and genealogical information.
Timeline
The MyHeritage user database is exfiltrated, capturing nearly all accounts created up to that date.
A security researcher finds a file named 'myheritage' on a private external server and notifies MyHeritage.
MyHeritage publicly discloses the breach the day after discovery, citing GDPR notification obligations.
The company convenes an incident-response team, recommends password resets and announces plans for two-factor authentication.
Have I Been Pwned loads 91,991,358 unique MyHeritage accounts.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/MyHeritage
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/myheritage-genealogy-site-announces-mega-breach-affecting-92-million-accounts/
- securityweek.comhttps://www.securityweek.com/92-million-user-credentials-lost-myheritage/
- vice.comhttps://www.vice.com/en/article/myheritage-hacked-data-breach-92-million/