MyHeritage — 92 Million Genealogy Accounts, Found by a Researcher Seven Months Later (2017)
If you have an account with MyHeritage, here’s what’s now in circulation.
The genealogy site lost email addresses and salted SHA-1 hashes in October 2017 and did not learn about it until a researcher found the file and told them, seven months later. No DNA data and no family trees were in it — a point worth stating plainly, because the opposite is widely assumed.
What happened
In October 2017 the genealogy website MyHeritage suffered a breach exposing more than 92 million customer records containing email addresses and salted SHA-1 password hashes. The incident was reported seven months later, after a security researcher discovered the file and contacted the company. In 2019 the data appeared for sale on a dark-web marketplace among the GnosticPlayers batches and began circulating more widely.
What was not in it
Start here, because the assumption runs the other way and the correction matters. No DNA data was exposed. No family trees were exposed. No payment details were exposed. The catalogue lists two data classes: email addresses and passwords.
This distinction is not a technicality. A genetic-data breach would be permanent and would implicate blood relatives who never used the service. This was a credential breach at a company that happens to hold genetic data — serious, but a different order of problem. Pages that blur the two frighten readers about a harm that did not occur while under-serving the one that did.
Salted SHA-1, and seven months of silence
The hashes were salted, so mass cracking across the whole set was not possible; but SHA-1 is fast, so weak passwords fell to targeted attempts. The realistic reading is the same as for Zynga: guessable passwords are gone, long random ones held.
The more consequential number is seven months — and the way the company found out. MyHeritage did not detect this. An outside researcher found a file sitting on a private server and got in touch. Absent that, the disclosure interval would have been longer still, or indefinite.
Every user was making security decisions during those seven months on the belief that their credentials were intact. This is the same lesson as Deezer and LinkedIn arriving from a third direction: a breach check tells you what is known, and known lags real by months or years.
The identity-chain implication
Genealogy accounts are unusual in that their value to an attacker lies almost entirely outside the breached data. The email address confirms that a specific person researches their family history — and family-history services hold, and often display, relatives' names, birth years and locations.
Maiden names, birth towns and mothers' names are the standard answers to account-recovery questions across banking and email. A credential for a genealogy account is therefore a potential route to the material that unlocks accounts elsewhere — not because the breach exposed those facts, but because the account reaches them.
What to do now
What You Should Do
- Change the password if it was guessable — salted SHA-1 resists bulk cracking but not targeted attempts on weak passwords
- Enable 2FA on the account specifically, because its value is the family data it reaches rather than the credential itself
- Replace any security answers drawing on maiden names, birth towns or relatives — a genealogy account is where those facts live
- Check the same address against Dubsmash, MyFitnessPal and Canva from the same 2019 listings
- Note that no DNA or family-tree data was in this breach, and disregard claims otherwise
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
MySpace — 360 Million Accounts, and the Weakest Password Storage of Any Major Breach (2008)
MySpace stored the SHA-1 hash of only the first ten characters of your password, lowercased, with no…
Zynga — 173 Million Words With Friends Accounts (2019)
The maker of Words With Friends lost 173 million accounts with salted SHA-1 passwords and, unusually…
LinkedIn — 164 Million Accounts, Unsalted SHA-1, Four Years in the Dark (2012)
Hacked in 2012, sold in 2016. LinkedIn stored passwords as unsalted SHA-1 and the vast majority were…