[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3qaxds8q4xblu":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":26,"seoTitle":27,"seoTitleEn":28,"seoDescription":27,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda488252d3","MyHeritage","MyHeritage Data Breach","myheritage","myheritage.com","2017-10-26T00:00:00.000Z","2019-02-20T21:04:04.000Z","2026-07-18T23:55:02.865Z","Verified breach record","https:\u002F\u002Fblog.myheritage.com\u002F2018\u002F06\u002Fmyheritage-statement-about-a-cybersecurity-incident\u002F",[15,17],"https:\u002F\u002Fwww.theregister.com\u002Fsecurity\u002F2019\u002F02\u002F11\u002F620-million-accounts-stolen-from-16-hacked-websites-now-for-sale-on-dark-web-seller-boasts\u002F665817",91991358,"known",null,"unknown","Critical",[24,25],"Email addresses","Passwords","\u003Cp>The MyHeritage data breach is a large-scale account data incident dated October 26, 2017, related to the genealogy and family history service. The verified scope is limited to 91,991,358 unique accounts. The dataset contains email addresses and passwords; the password field should not be considered plain text but as salted SHA-1 password hashes.\u003C\u002Fp>\u003Cp>The main risk in the MyHeritage incident is the combination of the email address and password hash in the same account data. A password hash is not as direct as a plain text password; however, it can pave the way for account takeover attempts for weak, short, predictable, or reused passwords from other services. The context of genealogy and family history can also make phishing messages themed around fake relative matches, old account warnings, or security notifications more convincing.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The verified data classes in the MyHeritage dataset are email addresses and passwords. The password field is in the form of SHA-1 password hashes with salt. Email addresses can be used for targeted phishing, account matching, old account alerts, and password reset scams. Password hashes, on the other hand, pose additional risks especially with weak passwords and password reuse.\u003C\u002Fp>\u003Cp>In this incident, plain text passwords, payment cards, phone numbers, physical addresses, ID documents, DNA profiles, or family tree content should not be considered as verified leaked material. Nevertheless, when the email and password fields are found together, attackers may try the same combination on email, social media, cloud storage, shopping, family history, and work accounts.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The breach date for MyHeritage should be kept as October 26, 2017, the record addition date as February 20, 2019, and the number of affected accounts as 91,991,358. The company announcement explains that the file contained the email addresses and hashed passwords of users who had opened a MyHeritage account; the file was seen on a private server outside the company.\u003C\u002Fp>\u003Cp>While explaining the scope, family trees, DNA data, payment information, credit cards, identification documents, phone numbers, or physical addresses should not be presented as definite leakage areas. The company has reported that payment information is stored with third-party payment providers, and family tree and DNA data are kept in separate systems, with no evidence of unauthorized access to these systems. Therefore, a MyHeritage record should be considered not a sensitive genealogy data leak, but a high-volume account ID and password reuse risk.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The main group at risk consists of users who opened a MyHeritage account on or before October 26, 2017. People who use the same password on their email account, social media, cloud storage, shopping sites, genealogy services, or work account carry a higher risk. Even if old accounts are forgotten, the risk continues if the same password is valid on other services.\u003C\u002Fp>\u003Cp>Users who are sensitive to messages themed around family trees, family history, or DNA results should also be cautious in terms of targeted phishing. When attackers know there is a real MyHeritage account, they may contact the user under the pretense of family connections, security alerts, old subscriptions, photo archives, or relative matches. For people using corporate email, the risk can also extend to password attempts on the work account.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who have been matched on MyHeritage should change their passwords on their MyHeritage account and on all accounts where the same password is used. Priority should be given to email accounts, social media, cloud storage, shopping, payment, family history, and work accounts. New passwords should be long, unique, and chosen from values stored in a password manager.\u003C\u002Fp>\u003Cp>Two-factor authentication should be enabled on all major accounts, active sessions and connected devices should be checked, and unrecognized sessions should be closed. For messages themed around family trees, DNA results, relative matches, or old account security, before clicking on any link, you should log in through the service's known web address or official app. One-time codes, account passwords, or recovery links should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a unique password for each service, a password manager, and two-factor authentication are the basic defense. Maintaining the same email and password pattern for years on services with strong personal context, such as family history and photo archives, makes it easier for data from old breaches to be tried on new accounts. Using a separate email address or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Users should regularly review old family history accounts, close accounts that are no longer necessary, and keep recovery emails and security notifications up to date. When an email and password hash is exposed, the risk is not limited to a single site; the password repetition must be cleared and long-term vigilance against targeted phishing messages is required.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in the MyHeritage dataset. A positive result indicates that the email address is present in this dataset and that the verified data fields should be included in the risk assessment. This result does not prove that DNA, family tree, payment card, or identity document information has been exposed; protective measures should be planned around email and password risk.\u003C\u002Fp>\u003Cp>A negative result only means that no match was found in the MyHeritage dataset; it does not eliminate the possibility of being present in other data breaches. Users who receive a positive result should reset their password, enable two-factor authentication, review old sessions, and verify genealogy or family history-themed security messages through a separate channel.\u003C\u002Fp>","","MyHeritage Data Breach (92 Million Reported Records)","MyHeritage Data Breach. 92 Million reported records were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fmyheritage_com.webp",false,{"name":7,"sector":33,"country":34,"website":10,"websiteArchiveUrl":27,"websiteStatus":27,"websiteCheckedAt":20},"Genealogy \u002F Family History","Israel"]