Skip to content
Back to Blog
high severity October 26, 2017 · 3 min read

MyHeritage — 92 Million Genealogy Accounts, Found by a Researcher Seven Months Later (2017)

If you are a customer of MyHeritage, here’s what’s now in circulation.

The genealogy site lost email addresses and salted SHA-1 hashes in October 2017 and did not learn about it until a researcher found the file and told them, seven months later. No DNA data and no family trees were in it — a point worth stating plainly, because the opposite is widely assumed.

A family tree beside an account credential

What happened

In October 2017 the genealogy website MyHeritage suffered a breach exposing more than 92 million customer records containing email addresses and salted SHA-1 password hashes. The incident was reported seven months later, after a security researcher discovered the file and contacted the company. In 2019 the data appeared for sale on a dark-web marketplace among the GnosticPlayers batches and began circulating more widely.

Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

What was not in it

Start here, because the assumption runs the other way and the correction matters. No DNA data was exposed. No family trees were exposed. No payment details were exposed. The catalogue lists two data classes: email addresses and passwords.

This distinction is not a technicality. A genetic-data breach would be permanent and would implicate blood relatives who never used the service. This was a credential breach at a company that happens to hold genetic data — serious, but a different order of problem. Pages that blur the two frighten readers about a harm that did not occur while under-serving the one that did.

Salted SHA-1, and seven months of silence

The hashes were salted, so mass cracking across the whole set was not possible; but SHA-1 is fast, so weak passwords fell to targeted attempts. The realistic reading is the same as for Zynga: guessable passwords are gone, long random ones held.

The more consequential number is seven months — and the way the company found out. MyHeritage did not detect this. An outside researcher found a file sitting on a private server and got in touch. Absent that, the disclosure interval would have been longer still, or indefinite.

Every user was making security decisions during those seven months on the belief that their credentials were intact. This is the same lesson as Deezer and LinkedIn arriving from a third direction: a breach check tells you what is known, and known lags real by months or years.

The identity-chain implication

Genealogy accounts are unusual in that their value to an attacker lies almost entirely outside the breached data. The email address confirms that a specific person researches their family history — and family-history services hold, and often display, relatives' names, birth years and locations.

Maiden names, birth towns and mothers' names are the standard answers to account-recovery questions across banking and email. A credential for a genealogy account is therefore a potential route to the material that unlocks accounts elsewhere — not because the breach exposed those facts, but because the account reaches them.

What to do now

What You Should Do

  1. Change the password if it was guessable — salted SHA-1 resists bulk cracking but not targeted attempts on weak passwords
  2. Enable 2FA on the account specifically, because its value is the family data it reaches rather than the credential itself
  3. Replace any security answers drawing on maiden names, birth towns or relatives — a genealogy account is where those facts live
  4. Check the same address against Dubsmash, MyFitnessPal and Canva from the same 2019 listings
  5. Note that no DNA or family-tree data was in this breach, and disregard claims otherwise

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a MyHeritage customer?
MyHeritage is one listing. Your email is probably in others.
92.0M customer records accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed October 26, 2017
Last reviewed July 22, 2026
Affected 92.0M customer records
Data exposed Email addressesPasswords
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email