Back to Blog
high severity October 26, 2017 · 3 min read

MyHeritage — 92 Million Genealogy Accounts, Found by a Researcher Seven Months Later (2017)

If you have an account with MyHeritage, here’s what’s now in circulation.

The genealogy site lost email addresses and salted SHA-1 hashes in October 2017 and did not learn about it until a researcher found the file and told them, seven months later. No DNA data and no family trees were in it — a point worth stating plainly, because the opposite is widely assumed.

A family tree beside an account credential

What happened

In October 2017 the genealogy website MyHeritage suffered a breach exposing more than 92 million customer records containing email addresses and salted SHA-1 password hashes. The incident was reported seven months later, after a security researcher discovered the file and contacted the company. In 2019 the data appeared for sale on a dark-web marketplace among the GnosticPlayers batches and began circulating more widely.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

What was not in it

Start here, because the assumption runs the other way and the correction matters. No DNA data was exposed. No family trees were exposed. No payment details were exposed. The catalogue lists two data classes: email addresses and passwords.

This distinction is not a technicality. A genetic-data breach would be permanent and would implicate blood relatives who never used the service. This was a credential breach at a company that happens to hold genetic data — serious, but a different order of problem. Pages that blur the two frighten readers about a harm that did not occur while under-serving the one that did.

Salted SHA-1, and seven months of silence

The hashes were salted, so mass cracking across the whole set was not possible; but SHA-1 is fast, so weak passwords fell to targeted attempts. The realistic reading is the same as for Zynga: guessable passwords are gone, long random ones held.

The more consequential number is seven months — and the way the company found out. MyHeritage did not detect this. An outside researcher found a file sitting on a private server and got in touch. Absent that, the disclosure interval would have been longer still, or indefinite.

Every user was making security decisions during those seven months on the belief that their credentials were intact. This is the same lesson as Deezer and LinkedIn arriving from a third direction: a breach check tells you what is known, and known lags real by months or years.

The identity-chain implication

Genealogy accounts are unusual in that their value to an attacker lies almost entirely outside the breached data. The email address confirms that a specific person researches their family history — and family-history services hold, and often display, relatives' names, birth years and locations.

Maiden names, birth towns and mothers' names are the standard answers to account-recovery questions across banking and email. A credential for a genealogy account is therefore a potential route to the material that unlocks accounts elsewhere — not because the breach exposed those facts, but because the account reaches them.

What to do now

What You Should Do

  1. Change the password if it was guessable — salted SHA-1 resists bulk cracking but not targeted attempts on weak passwords
  2. Enable 2FA on the account specifically, because its value is the family data it reaches rather than the credential itself
  3. Replace any security answers drawing on maiden names, birth towns or relatives — a genealogy account is where those facts live
  4. Check the same address against Dubsmash, MyFitnessPal and Canva from the same 2019 listings
  5. Note that no DNA or family-tree data was in this breach, and disregard claims otherwise

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a MyHeritage customer?
MyHeritage is one breach. Your email is probably in others.
92.0M customer records accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed October 26, 2017
Last reviewed July 22, 2026
Affected 92.0M customer records
Data exposed Email addressesPasswords
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email