Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
MyHeritage

MyHeritage Vendor Cyber Rating & Cyber Score

myheritage.com

MyHeritage is the leading global discovery platform for exploring family history. With billions of historical records and family tree profiles, and with sophisticated matching technologies that work across all its assets, MyHeritage allows users to discover their past and empower their future. MyHeritage DNA is one of the world’s largest consumer DNA databases, with 5.4 million customers. MyHeritage is the most popular DNA test and family history service in Europe. Since 2020, MyHeritage is home to the world’s most advanced AI technologies for repairing, enhancing, colorizing, and animating historical photos. Working at MyHeritage means developing pioneering technologies and integrating AI to deliver powerful discoveries to our 104


MyHeritage A.I CyberSecurity Scoring

MyHeritage
Company Information
Website:http://www.myheritage.com
Employees number:546
Number of followers:32,037
NAICS:5112
Industry Type:Software Development
Homepage:myheritage.com
MyHeritage Risk Score (AI oriented)
Between 700 and 749
logo
MyHeritageSoftware Development
Updated:
29/03/2026
734/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MyHeritage Global Score (TPRM)
xxxx
logo
MyHeritageSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MyHeritage
MyHeritageModerate
Current Score
734Ba (MODERATE)
01000
6 incidents
-81.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
588Before Incident
JUNE 2026
683Before Incident
Breach
01 Jun 2026MyHeritage
23andMe: California Attorney General sues 23andMe for security breach

23andMe Data Breach Impacting 7 Million Users

584After Incident
CRITICAL-99
23A1780359968
23andMe Faces Lawsuit Over 2023 Data Breach Impacting 7 Million Users The California Attorney General, Rob Bonta, has filed a lawsuit against genetic-testing company 23andMe (now operating as Chrome Holding Co.) for its handling of a 2023 data breach that exposed the sensitive information of nearly 7 million users, including over 850,000 Californians. The complaint alleges that 23andMe failed to implement basic security measures, misled customers about the breach’s severity, and violated multiple state laws, including the Genetic Information Privacy Act and the California Consumer Privacy Act. The breach, which occurred over five months, stemmed from a credential-stuffing attack, where hackers exploited weak or reused passwords from other breaches including a prior incident at genealogy site MyHeritage, a 23andMe partner. Once inside, attackers exploited a coding flaw in the company’s “DNA Relatives” feature, allowing them to access ancestry reports, family histories, and health-related genetic data. The stolen information was later offered for sale on the dark web, with hackers specifically targeting data belonging to Asian-Pacific Islander and Jewish users amid rising hate crimes. 23andMe initially downplayed the incident, publicly confirming only 14,000 compromised accounts while withholding details about the broader exposure. The California Department of Justice’s investigation found that the company’s security practices “fell below industry standards”, despite its claims of robust protections. The lawsuit also accuses 23andMe of misleading customers by denying a security incident even after hackers revealed exploitable vulnerabilities during ransom negotiations. Founded in 2006, 23andMe was the first direct-to-consumer DNA testing company but faced financial struggles, filing for bankruptcy in 2023. Its assets were later acquired by the 23andMe Research Institute, a nonprofit that has distanced itself from the lawsuit, stating it was not involved in the events leading to the breach. The legal action seeks accountability for what Bonta described as a failure to “meet its obligation under California law to keep [users’] information safe.” The case highlights the risks of inadequate cybersecurity in handling highly sensitive genetic and personal data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain, potential targeting of ethnic groups amid rising hate crimes
IMPACT
Data Compromised: Ancestry reports, family histories, health-related genetic dataSystems Affected: 23andMe user accounts, 'DNA Relatives' featureBrand Reputation Impact: Significant, due to lawsuit and misrepresentation of breach severityLegal Liabilities: Lawsuit filed by California Attorney General for violating Genetic Information Privacy Act and California Consumer Privacy ActIdentity Theft Risk: High, due to exposure of sensitive genetic and personal data
DATA BREACH
Type Of Data Compromised: Genetic data, ancestry reports, family histories, health-related informationNumber Of Records Exposed: 7 million usersSensitivity Of Data: High (genetic and personally identifiable information)Data Exfiltration: Yes, data sold on dark webPersonally Identifiable Information: Yes (genetic data, family histories, health information)
MAY 2026
734Before Incident
APRIL 2026
734Before Incident
MARCH 2026
733Before Incident
FEBRUARY 2026
733Before Incident
JANUARY 2026
733Before Incident
DECEMBER 2025
732Before Incident
NOVEMBER 2025
732Before Incident
OCTOBER 2025
731Before Incident
SEPTEMBER 2025
531Before Incident
Breach
25 Sep 2025MyHeritage
23andMe

23andMe Data Breach and Bankruptcy Settlement

467After Incident
CRITICAL-64
23A0702607092625
The genetic testing company 23andMe faced a significant data breach exposing customers' personal and genetic information. The breach led to legal claims from affected users, prompting the company to propose settlements as part of its ongoing Chapter 11 bankruptcy proceedings. The exposed data included sensitive customer details, raising concerns over privacy, identity theft, and potential misuse of genetic information. The breach’s financial and reputational fallout contributed to the company’s restructuring efforts, with a judge reviewing settlement approvals to resolve customer claims. The incident underscores the severe consequences of failing to protect highly personal data in the biotech sector, particularly when such information can have long-term implications for individuals' health, insurance, and security.
INCIDENT DETAILS -
TYPE
Data Breach
DATA BREACH
Personally Identifiable Information (PII)Genetic DataSensitivity Of Data: High
AUGUST 2025
730Before Incident
OCTOBER 2023
716Before Incident
Breach
06 Oct 2023MyHeritage
Chrome Holding Co.: Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach

California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users

620After Incident
CRITICAL-96
CHR1779992999
California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users California Attorney General Rob Bonta has filed a lawsuit against genetic testing company Chrome Holding Co. (formerly 23andMe), alleging the company failed to protect sensitive customer data and misled the public about a 2023 data breach that compromised nearly 7 million users, including 855,541 Californians. The breach exposed highly personal information, including genetic health predispositions, ancestry details, family histories, and ethnicity data, which was later sold on the dark web. The attack, which went undetected for five months, began when a threat actor used credential stuffing a method exploiting reused passwords from prior breaches, including a 2021 MyHeritage incident to access 14,000 23andMe accounts. The hacker then exploited a coding vulnerability in the company’s "DNA Relatives" feature, allowing them to scrape data from millions of users. The stolen information was later advertised for sale on the dark web, with sellers explicitly targeting Asian American, Pacific Islander, and Jewish users a particularly alarming detail given the rise in anti-AAPI and antisemitic hate crimes at the time. Despite 23andMe’s public claims of robust security, the California Department of Justice’s investigation found the company ignored known vulnerabilities, failed to detect the attack for months, and neglected basic safeguards against credential stuffing. Even after the breach was exposed, 23andMe downplayed its severity, falsely asserting that no internal systems were compromised and that the stolen "DNA Relatives" data was effectively public. Meanwhile, the company was secretly negotiating a ransom payment with the hacker, who revealed multiple security flaws during the process. The lawsuit alleges violations of California’s Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act, citing 23andMe’s failure to implement reasonable security measures and its deceptive statements about the breach. The case is separate from an ongoing bankruptcy dispute over the potential sale of Californians’ genetic data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data exfiltration and sale on dark web
IMPACT
Data Compromised: Genetic health predispositions, ancestry details, family histories, ethnicity data, personally identifiable informationBrand Reputation Impact: Significant (allegations of deceptive statements and security failures)Legal Liabilities: Violations of California’s Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and California Consumer Privacy ActIdentity Theft Risk: High (genetic and personal data exposed)
DATA BREACH
Genetic health predispositionsAncestry detailsFamily historiesEthnicity dataPersonally identifiable informationNumber Of Records Exposed: 7,000,000Sensitivity Of Data: High (genetic and personal data)
JUNE 2023
579Before Incident
Breach
16 Jun 2023MyHeritage
23andMe

23andMe Data Breach (2023)

481After Incident
CRITICAL-98
23A4894348111825
In 2023, 23andMe suffered a major data breach exposing highly sensitive genetic and ancestry data of nearly 7 million users. The compromised information included chromosomal haplogroups, family tree details, and ancestry profiles, with ethically charged consequences—such as curated dark web lists targeting individuals of Jewish and Chinese descent. Initially, the company blamed users for weak passwords, exacerbating public distrust. The fallout led to a costly class-action lawsuit, severe reputational damage, and heightened scrutiny over the company’s data stewardship practices. The breach underscored the risks of mishandling biometric and genetic data, which, unlike financial records, cannot be changed if exposed. The incident also highlighted systemic failures in incident response, transparency, and ethical data management, reinforcing the need for stricter protections around health-related and personally identifiable information (PII).
INCIDENT DETAILS -
TYPE
Data BreachData MismanagementEthical Violation
MOTIVATION
Financial Gain (Dark Web Sales)Targeted Data ExfiltrationEthnic/Ancestral Profiling
IMPACT
Class-Action Lawsuit CostsReputational Damage (Significant)Ancestry InformationChromosomal HaplogroupsFamily Tree UploadsPersonally Identifiable Information (PII)Legal and Regulatory ScrutinyCustomer Trust ErosionHigh Volume (Due to Sensitive Data Exposure)Severe DamageLoss of Consumer TrustClass-Action LawsuitPotential Regulatory FinesHigh (Due to PII and Genetic Data Exposure)
DATA BREACH
Genetic DataAncestry InformationFamily Tree DataPII (Potential)Number Of Records Exposed: 7,000,000Sensitivity Of Data: Extremely High (Genetic and Ethnic Information)Dark Web SalesCurated Lists by AncestryData Encryption: Unknown (Likely Inadequate)User UploadsGenetic ReportsFamily Tree DataNames (Likely)Ancestry DetailsPotential Addresses/Contact Info
DECEMBER 2021
699Before Incident
Breach
14 Dec 2021MyHeritage
23andMe: Arizona joins $18M multi-state settlement with 23andMe over breach

42 States Reach $18M Settlement with 23andMe Over 2023 Data Breach

505After Incident
CRITICAL-194
23A1784075183
42 States Reach $18M Settlement with 23andMe Over 2023 Data Breach A coalition of 42 states, including Arizona, has finalized an $18 million settlement with biotech company 23andMe following a 2023 data breach that exposed the private information of millions of customers. The breach, which compromised sensitive genetic and personal data, prompted a multi-state investigation into the company’s security practices. The settlement resolves allegations that 23andMe failed to implement adequate safeguards to protect user data, leading to unauthorized access. While details of the breach’s scope and the specific vulnerabilities exploited remain under review, the agreement requires the company to enhance its cybersecurity measures and improve transparency around future incidents. The case underscores growing regulatory scrutiny over data privacy in the genetic testing industry, where personal and health-related information is increasingly targeted by cyber threats. The financial penalty and mandated reforms aim to hold 23andMe accountable while setting a precedent for similar cases.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $18,000,000Data Compromised: Sensitive genetic and personal dataLegal Liabilities: Multi-state investigation and settlement
DATA BREACH
Type Of Data Compromised: Genetic and personal dataNumber Of Records Exposed: MillionsSensitivity Of Data: HighPersonally Identifiable Information: Yes
JUNE 2018
756Before Incident
Breach
01 Jun 2018MyHeritage
MyHeritage

MyHeritage Security Breach

623After Incident
HIGH-133
MYH214181122
MyHeritage announced a security breach. An attacker made off with account details for over 92 million MyHeritage users. A security researcher found an archive on a third-party server containing the personal details of 92,283,889 MyHeritage users. The archive contained only emails and hashed passwords, but not payment card details or DNA test results. User accounts are safe, as the passwords were hashed using a per-user unique cryptographic key.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
emailshashed passwords
DATA BREACH
emailshashed passwordsSensitivity Of Data: Mediumemails

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MyHeritage ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in October 2025 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in September 2025 ?
?
What was MyHeritage's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on MyHeritage's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MyHeritage ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MyHeritage's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?