MyHeritage A.I CyberSecurity Scoring
MyHeritage
Company Information
Website:http://www.myheritage.com
Employees number:546
Number of followers:32,037
NAICS:5112
Industry Type:Software Development
Homepage:myheritage.com
MyHeritage Risk Score (AI oriented)
Between 700 and 749
MyHeritageSoftware Development
Updated:
29/03/2026
29/03/2026
734/1000
Moderate
Ba
MyHeritage Global Score (TPRM)
xxxx
MyHeritageSoftware Development
Score locked

MyHeritageModerate
Current Score
734Ba (MODERATE)
01000
6 incidents
-81.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
588
JUNE 2026
683
Breach
01 Jun 2026 • MyHeritage
23andMe: California Attorney General sues 23andMe for security breach
23andMe Data Breach Impacting 7 Million Users
584
CRITICAL-99
23A1780359968
23andMe Faces Lawsuit Over 2023 Data Breach Impacting 7 Million Users
The California Attorney General, Rob Bonta, has filed a lawsuit against genetic-testing company 23andMe (now operating as Chrome Holding Co.) for its handling of a 2023 data breach that exposed the sensitive information of nearly 7 million users, including over 850,000 Californians. The complaint alleges that 23andMe failed to implement basic security measures, misled customers about the breach’s severity, and violated multiple state laws, including the Genetic Information Privacy Act and the California Consumer Privacy Act.
The breach, which occurred over five months, stemmed from a credential-stuffing attack, where hackers exploited weak or reused passwords from other breaches including a prior incident at genealogy site MyHeritage, a 23andMe partner. Once inside, attackers exploited a coding flaw in the company’s “DNA Relatives” feature, allowing them to access ancestry reports, family histories, and health-related genetic data. The stolen information was later offered for sale on the dark web, with hackers specifically targeting data belonging to Asian-Pacific Islander and Jewish users amid rising hate crimes.
23andMe initially downplayed the incident, publicly confirming only 14,000 compromised accounts while withholding details about the broader exposure. The California Department of Justice’s investigation found that the company’s security practices “fell below industry standards”, despite its claims of robust protections. The lawsuit also accuses 23andMe of misleading customers by denying a security incident even after hackers revealed exploitable vulnerabilities during ransom negotiations.
Founded in 2006, 23andMe was the first direct-to-consumer DNA testing company but faced financial struggles, filing for bankruptcy in 2023. Its assets were later acquired by the 23andMe Research Institute, a nonprofit that has distanced itself from the lawsuit, stating it was not involved in the events leading to the breach.
The legal action seeks accountability for what Bonta described as a failure to “meet its obligation under California law to keep [users’] information safe.” The case highlights the risks of inadequate cybersecurity in handling highly sensitive genetic and personal data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
734
APRIL 2026
734
MARCH 2026
733
FEBRUARY 2026
733
JANUARY 2026
733
DECEMBER 2025
732
NOVEMBER 2025
732
OCTOBER 2025
731
SEPTEMBER 2025
531
Breach
25 Sep 2025 • MyHeritage
23andMe
23andMe Data Breach and Bankruptcy Settlement
467
CRITICAL-64
23A0702607092625
The genetic testing company 23andMe faced a significant data breach exposing customers' personal and genetic information. The breach led to legal claims from affected users, prompting the company to propose settlements as part of its ongoing Chapter 11 bankruptcy proceedings. The exposed data included sensitive customer details, raising concerns over privacy, identity theft, and potential misuse of genetic information. The breach’s financial and reputational fallout contributed to the company’s restructuring efforts, with a judge reviewing settlement approvals to resolve customer claims. The incident underscores the severe consequences of failing to protect highly personal data in the biotech sector, particularly when such information can have long-term implications for individuals' health, insurance, and security.
INCIDENT DETAILS -
TYPE
DATA BREACH
REFERENCES
AUGUST 2025
730
OCTOBER 2023
716
Breach
06 Oct 2023 • MyHeritage
Chrome Holding Co.: Attorney General Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach
California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users
620
CRITICAL-96
CHR1779992999
California AG Sues 23andMe Over Massive Data Breach Exposing Genetic and Personal Data of 7 Million Users
California Attorney General Rob Bonta has filed a lawsuit against genetic testing company Chrome Holding Co. (formerly 23andMe), alleging the company failed to protect sensitive customer data and misled the public about a 2023 data breach that compromised nearly 7 million users, including 855,541 Californians. The breach exposed highly personal information, including genetic health predispositions, ancestry details, family histories, and ethnicity data, which was later sold on the dark web.
The attack, which went undetected for five months, began when a threat actor used credential stuffing a method exploiting reused passwords from prior breaches, including a 2021 MyHeritage incident to access 14,000 23andMe accounts. The hacker then exploited a coding vulnerability in the company’s "DNA Relatives" feature, allowing them to scrape data from millions of users. The stolen information was later advertised for sale on the dark web, with sellers explicitly targeting Asian American, Pacific Islander, and Jewish users a particularly alarming detail given the rise in anti-AAPI and antisemitic hate crimes at the time.
Despite 23andMe’s public claims of robust security, the California Department of Justice’s investigation found the company ignored known vulnerabilities, failed to detect the attack for months, and neglected basic safeguards against credential stuffing. Even after the breach was exposed, 23andMe downplayed its severity, falsely asserting that no internal systems were compromised and that the stolen "DNA Relatives" data was effectively public. Meanwhile, the company was secretly negotiating a ransom payment with the hacker, who revealed multiple security flaws during the process.
The lawsuit alleges violations of California’s Genetic Information Privacy Act, Reasonable Data Security Law, False Advertising Law, Unfair Competition Law, and the California Consumer Privacy Act, citing 23andMe’s failure to implement reasonable security measures and its deceptive statements about the breach. The case is separate from an ongoing bankruptcy dispute over the potential sale of Californians’ genetic data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2023
579
Breach
16 Jun 2023 • MyHeritage
23andMe
23andMe Data Breach (2023)
481
CRITICAL-98
23A4894348111825
In 2023, 23andMe suffered a major data breach exposing highly sensitive genetic and ancestry data of nearly 7 million users. The compromised information included chromosomal haplogroups, family tree details, and ancestry profiles, with ethically charged consequences—such as curated dark web lists targeting individuals of Jewish and Chinese descent. Initially, the company blamed users for weak passwords, exacerbating public distrust. The fallout led to a costly class-action lawsuit, severe reputational damage, and heightened scrutiny over the company’s data stewardship practices. The breach underscored the risks of mishandling biometric and genetic data, which, unlike financial records, cannot be changed if exposed. The incident also highlighted systemic failures in incident response, transparency, and ethical data management, reinforcing the need for stricter protections around health-related and personally identifiable information (PII).
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2021
699
Breach
14 Dec 2021 • MyHeritage
23andMe: Arizona joins $18M multi-state settlement with 23andMe over breach
42 States Reach $18M Settlement with 23andMe Over 2023 Data Breach
505
CRITICAL-194
23A1784075183
42 States Reach $18M Settlement with 23andMe Over 2023 Data Breach
A coalition of 42 states, including Arizona, has finalized an $18 million settlement with biotech company 23andMe following a 2023 data breach that exposed the private information of millions of customers. The breach, which compromised sensitive genetic and personal data, prompted a multi-state investigation into the company’s security practices.
The settlement resolves allegations that 23andMe failed to implement adequate safeguards to protect user data, leading to unauthorized access. While details of the breach’s scope and the specific vulnerabilities exploited remain under review, the agreement requires the company to enhance its cybersecurity measures and improve transparency around future incidents.
The case underscores growing regulatory scrutiny over data privacy in the genetic testing industry, where personal and health-related information is increasingly targeted by cyber threats. The financial penalty and mandated reforms aim to hold 23andMe accountable while setting a precedent for similar cases.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2018
756
Breach
01 Jun 2018 • MyHeritage
MyHeritage
MyHeritage Security Breach
623
HIGH-133
MYH214181122
MyHeritage announced a security breach.
An attacker made off with account details for over 92 million MyHeritage users.
A security researcher found an archive on a third-party server containing the personal details of 92,283,889 MyHeritage users.
The archive contained only emails and hashed passwords, but not payment card details or DNA test results.
User accounts are safe, as the passwords were hashed using a per-user unique cryptographic key.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MyHeritage ??
What was MyHeritage's A.I Rankiteo Cyber Score in June 2026 ??
What was MyHeritage's A.I Rankiteo Cyber Score in May 2026 ??
What was MyHeritage's A.I Rankiteo Cyber Score in April 2026 ??
What was MyHeritage's A.I Rankiteo Cyber Score in March 2026 ??
What was MyHeritage's A.I Rankiteo Cyber Score in February 2026 ??
What was MyHeritage's A.I Rankiteo Cyber Score in January 2026 ??
What was MyHeritage's A.I Rankiteo Cyber Score in December 2025 ??
What was MyHeritage's A.I Rankiteo Cyber Score in November 2025 ??
What was MyHeritage's A.I Rankiteo Cyber Score in October 2025 ??
What was MyHeritage's A.I Rankiteo Cyber Score in September 2025 ??
What was MyHeritage's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on MyHeritage's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MyHeritage ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MyHeritage's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?