.

.

Sunday, August 23, 2020

GEDmatch Security Breach

Please note that information retrieved from the GEDmatch breach may be being used to send phishing emails intending to lure users into signing into a fake website set up to look like MyHeritage, but is not. If you receive an email that seems suspicious or has the title “Ethnicity Estimate v2,” do not click. Do delete that email. Please read the MyHeritage article, here. To be very clear, MyHeritage has NOT been breached, but bad actors have harvested emails and are using them to try to lure targeted MyHeritage users.

Original article:

I always hate to have to report security breaches within the genealogy community, but GEDmatch not only experienced a breach over the weekend, they are still down while the situation is under investigation.

In a nutshell, for about 3 hours on Sunday, July 19th, all of the accounts, including law enforcement kits, were available in match lists for everyone. Also, kits that had been opted out of law enforcement matching were apparently, based on screen shots of their security settings taken by users who signed on during that time, also available to law enforcement in match lists.

Here are the three announcements on their Facebook page in order of posting.

The first one was posted on July 19 at 6:09 PM.

The update was posted on Monday, July 20th. GEDmatch was up for part of the day, but is now down again and will be for some time.