Skip to content
June 19, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • 92 million MyHeritage users were leaked
  • Data Leak

92 million MyHeritage users were leaked

Do Son June 6, 2018 2 minutes read
Add as a preferred
source on Google

MyHeritage announced that the e-mail address and password information associated with the company’s 92 million accounts had been stolen by hackers. MyHeritage said that the company’s security administrator received a message from a researcher who found a file named “MyHeritage” on a private server outside the company that contained 92,283,889 MyHeritage accounts with the email address and encryption password.

MyHeritage allows users to create genealogy, search histories and find potential loved ones. The company was founded in Israel in 2003 and launched MyHeritage DNA in 2016. Users simply send a saliva sample for genetic testing. The site currently has 96 million users, of which 1.4 million have been genetically tested.

According to MyHeritage, the vulnerability occurred on October 26, 2017, and the affected users were registered before that day. The company also stated that they do not store user passwords. All passwords are encrypted using a so-called single-hash method. Different users’ data needs to be accessed using different keys.

“Our Information Security Team received the file from the security researcher, reviewed it, and confirmed that its contents originated from MyHeritage and included all the email addresses of users who signed up to MyHeritage up to October 26, 2017, and their hashed passwords.“

However, in previous hacking incidents, such mechanisms were hacked to convert passwords. If this is the case, the hackers can get their personal information after logging in to the user account, including the identity of the family member. However, even if a hacker can enter a user account, it is unlikely that the original genetic information will be easily accessible because it is necessary to confirm this by downloading the content.

In its statement, the company emphasized that DNA data is stored on “isolated systems, separate from the system that holds the e-mail, and contains an extra layer of security.”

MyHeritage has formed a 24/7 support team to help the affected users. The company also plans to hire an independent network security company to investigate the matter and possibly strengthen security measures. At the same time, they also advise users to change their passwords.

Suggested Reading: To find more info about DNA testing companies, you can read this post. The website provides In-depth and impartial reviews of leading DNA test kits, user-generated reviews of every DNA test kit we tested, and detailed kit comparisons to name a few.

Related coverage

  • Verizon Call Filter App Vulnerability Exposed Call Records of Millions
  • Car-sharing company GoGet was compromised, tens of thousands of members info leak
  • “Stylish” browser extension collect user information
  • LINE Data Breach Expands: Investigation Uncovers More Compromised Data
  • Researchers found a MSSQL database that contains information of 1.3 million people

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: MyHeritage leak

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-55884
    ## Summary The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints...
  • CVE-2026-9142CVSS 9.1
    There is an insecure default credentials vulnerability in NI grpc-device when TLS...
  • CVE-2026-54051CVSS 9.9
    ## Summary The agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`),...
  • CVE-2026-48137CVSS 9.1
    There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband...
  • CVE-2026-50242CVSS 10.0
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass...
  • CVE-2026-56142CVSS 9.6
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation...
  • CVE-2026-56141CVSS 9.8
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover...
  • CVE-2026-54414CVSS 9.8
    FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload...
  • CVE-2026-7515CVSS 9.8
    The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion...
  • CVE-2026-8713CVSS 9.1
    The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.