The Dangerous, Dark Side of AI, and How to Protect Yourself

This is the fifth article in the AI series.

  1. The first article, Your Wonderful AI Assistant – Sometimes Wrong, Never Unsure, Always Convincing, explains why I’m writing this series and what to expect.
  2. The second article, All About AI – What It Is, What It Isn’t, and Why It Matters, explains what AI is, where it “came from,” the different kinds of AI, how it’s “trained,” plus examples of how it does and doesn’t work well.
  3. The third article, AI Assistants – The Good, the Bad, the Ugly and the Unseen, explains how AI tools work (and fail), the different types of AI tools, and when you may encounter them, even when you don’t realize it. This article closes with examples of successfully using AI, along with AI educational resources.
  4. The fourth article, AI and Genealogy – Brick Walls, Breakthroughs and Blunders, explains how AI is being used in genealogy by vendors and by individuals personally. It includes controversial topics like photo and image generation and discusses expert GPT tools and how I’m using them successfully.

I suggest that you read these articles in publication order, as they build on each other.

This article is perhaps the most important of the series, is deadly serious, and merits a disclaimer.

Disclaimer: I am not a lawyer. This article and others in this series are provided for general educational and informational purposes only. Information contained in these articles does not constitute legal, financial, or cybersecurity advice. It is not intended to identify or discuss every current or future risk, scam, threat, law, protection, or recommended response. One size does not fit all, and the best response for your circumstances may differ from what is best for someone else or from what is recommended here. Technology, criminal tactics, laws, and best practices change rapidly, and some of this information will inevitably become outdated after publication. Readers should independently verify current information and consult an appropriately qualified professional when necessary.

The Dark Side

By now, you know how AI works, that it can be used for good or evil, and that Generative AI creates things.

The dangerous part is that, because AI is so convincing in ways we’ve never seen before, it’s now easier than ever for you to become a victim in a heartbeat. This can happen easily, and you’ll have no idea until it’s too late. Media, meaning videos, images, and audio, can be generated about you without your knowledge, using your voice or likeness. And yes, it’s utterly terrifying.

You may be saying to yourself, “I’ll never become a victim,” but the scope of what it means to be a victim has changed over time.

Some generative AI is created to scam you, but other AI is created to harm or manipulate you or others close to you.

Perhaps someone wants to manipulate you into doing something dangerous, buying something under false pretenses, paying a ransom, believing that something happened when it did not, or voting in a specific way. I’m not going to touch politics here – but suffice it to say that I’ve adopted a “believe nothing” position unless I can confirm whatever it is through multiple reputable sources from the time the event supposedly occurred.

The Warning Signs Have Shifted

We all thought we knew the hallmarks of scams – but all of that has changed, and our misplaced confidence is actually dangerous. Now, those fake emails no longer contain spelling errors and weird, awkward language. Instead, they look authentic, sound completely professional and may take you to fake websites that look identical to the real one, prompting you to enter your username and password. You see where this is going, right?

The bad guys know you’re still looking for those old signs and signals, so they have dramatically upped their game, allowing them to easily gain your confidence and falsely “earn” your trust.

Today’s scams are, for the most part, built on garnering your trust, then employing sophisticated trickery – and they are extremely convincing. I absolutely hate that we now have to be hypervigilant, bordering on paranoid, all the time, but we do.

In order to provide contract services to FamilyTreeDNA, I’m required to undergo periodic security and threat landscape training. Like any other mandatory training, I dread it, but it’s absolutely critical to stay on top of this because what AI can do and how it can do it are changing very rapidly. I’m grateful for the professional training from KnowBe4, a leader in the security industry, and I’m sharing what I’ve learned with you.

I am NOT mincing words here. You WILL encounter these situations, and if you’re not constantly aware and on your game, eventually, you WILL fall for one of them. Yes, there are upcoming CAPS and red letters. Yes, I’m yelling!

I’ve distilled my most recent training along with other cautions into Roberta’s Ten Rules of AI and Social Media Safety. AI and your online presence are inextricably interwoven.

Roberta’s Ten Rules of AI and Social Media Safety

Rule 1: STOP! DO NOT CLICK!

Always engage your brain before your fingers.

I don’t mean it’s OK to click from time to time because you think the email is from someone you know or a business entity you do business with.

I mean do not click ever, with very few exceptions. One example is 2FA.

2FA (two-factor authentication) and some other systems will send you a link in your email immediately after you make the request. You will receive the email or text immediately, and you will be expecting it. That’s the key here. You asked for and are expecting this interaction now. Anything else, don’t click. Not tomorrow or the next day if you didn’t request something again. Regardless of how authentic it looks.

If you receive any other type of email indicating that there is something you need to do, go to the normal website DIRECTLY by typing it in and sign in to take care of that task.

The bad guys know that you’re periodically going to receive emails from, say, your insurance company, Social Security, or your bank, and they know exactly what they look like – so they create a copy of the authentic email and insert malicious links THAT LOOK COMPLETELY LEGITIMATE. Those fake links take you to exact imitations of the website you’re used to working with.

Here’s an example that I received today.

I received this e-mail, supposedly from Backblaze, the company that I use for my offsite system backups. What do you think would happen if I clicked on the “Backup Dashboard” link or the FAQ link?

You know exactly what this “Dashboard” link would look like – the real one. The malicious dashboard is going to prompt me to sign in, which gives the crooks my user ID and password. The keys to the kingdom. What they could access or do next depends on how the attack is constructed and any other safeguards in place, but the consequences could be devastating – including backing up my entire computer system to their fake site. Literally everything.

Even the thought makes me queasy. Consider for a minute what’s on your computer. Our digital lives live there. For example, if you have a little file called “Passwords,” get rid of it.

If you’re thinking to yourself that I could easily catch this by looking at the email header, here’s what it says.

Click to enlarge any image.

Given that I’ve never received this kind of email before, how would I know what sending email address to expect? I wouldn’t, and the bad guys are counting on that.

What did I do? First, stop and breathe – but that wasn’t my first instinct – even with all this training.

It’s frightening to think my system hadn’t been backed up in two months, but on reflection, that doesn’t make any sense because I normally receive reports. So, by slowing down, and literally stopping to think, I recognized the warning signs of a malicious phishing attempt and DID NOT CLICK ON ANYTHING.

I stopped my reflexes and let my brain engage.

Respond after considerationDO NOT REACT!

Instead, I signed in to Backblaze independently, from my normal sign-in link on their website, and checked. Sure enough, I confirmed that it was a phishing attempt – and a pretty good one too. My backups are just fine, and my system had been backed up regularly.

Had I fallen for this, nothing might have happened right away, because what happens after you click on a malicious link or visit a malicious site has changed. The harm may occur silently now, not immediately, and potentially indirectly. Think about that password list. (By the way, I don’t have a file like that, but many people do.)

If you click on something and “nothing bad happened,” don’t be so quick to be relieved. Now the bad guys can install monitoring software on your computer without your knowledge. Then, when you email back and forth with, say, your real estate agent about buying that lot down the street, the bad guys spot an opportunity and send you an email from the “title company” with instructions for where to wire the money.

Or, the bad guys text you. Wait, you’re thinking, “They don’t have my phone number.” Yes, they do, and they know your name.

Whether you know it or not, your email address and phone number are already circulating publicly and are easily accessible. There’s even more information available on the dark web, including passwords from data breaches and the names of family members.

Crooks already know far more about you than you realize, and that’s exactly why phishing emails and messages are so convincing.

Rule 1: Do not click, because that’s how criminals gain entry.

Rule 2: NEVER, EVER SAVE PASSWORDS IN YOUR BROWSER FOR ANYTHING FINANCIAL.

Once criminals gain entry, they exploit their good fortune – and your misfortune.

If you have already clicked on a malicious link as described under Rule 1 and entered a password, change that password immediately.

Never store financial or other important passwords in your browser. Use a legitimate password manager instead. Forbes and Cybernews published 2026 password manager lists, or you can use Google to find current information.

While we’re on the subject of passwords, don’t reuse them. Let’s say you stored a password for a subscription site like Ancestry in your browser, but you used the same password for your bank account. You know what’s coming, right?

If one site is compromised, the bad guys will try using that sign-in information on financial and other sites. This hacking technique is called credential stuffing and is what 23andMe claimed caused its 2023 breach.

AI is getting so good at being bad that it takes less and less effort to compromise your system, retrieve and exploit this type of information, especially if you don’t have the time, resources, or desire to keep up with new and evolving threats.

Rule 2: Don’t reuse passwords, remove any password files from your computer, and never save passwords for financial sites in your browser.

Rule 3: DON’T BELIEVE YOUR EARS.

Do not assume a familiar, well-known voice belongs to the person it appears to belong to, even if sounds like a close family member.

I can’t believe I have to write this, because it sounds insane.

Generative AI may only need as little as two seconds of your voice to create a convincing voice clone that sounds exactly like you. That is not a typo, although a few more seconds, like 10 or 15, produce even better results. AI can then clone your voice and create a conversation. It takes very little tech savvy, and instructions are all over the internet.

These are known as deepfakes – which can also include videos.

Let me give you an example of how this works. You’re asleep at 3 AM. Your adult daughter calls and says she’s being held hostage and you need to come right now. Or a similar scenario. Someone is in jail, has been in a wreck, or is facing some other emergency.

You’ve been awakened from a dead sleep, and you’re groggy, confused, and terrified. The adrenaline is surging through your body, but your brain isn’t fully engaged.

It’s EXACTLY your daughter’s voice. Exactly. You have no reason to doubt it. There’s no mistaking it – that’s her on the phone, and she’s in grave danger. Your heart is pounding, you’re immediately frantic and desperate, and of course, you would do anything in the world to save her. Your body has been jerked from zero to about Mach 5 in less than two seconds

The LAST THING you’re going to do is stop and question whether it’s really her. Of course it is. You’ve known her for the past 30 years – since the day she was born. “Don’t you think I’d know my own child’s voice?”

The answer is no, you wouldn’t. And you’re the target.

STOP and assess. That’s exactly what you should do in the moment, even though your instincts are to rush and do something. It feels like betrayal to let one minute pass without moving forward, but it’s not betrayal, and that’s exactly what you need to do.

Stop, take a deep breath, and THINK!

Agree on a protocol in advance with anyone who might ever call you in this type of situation. Select either a keyword, short phrase (blueberry pie) or a couple of questions that only you and they would know the answer to and that you can easily remember. Nothing you’ve ever put on social media or used as a password or recovery information.

Select something that only they would know, and that would be impossible to guess. Safe words or phrases. Words or questions that only you and they know the answer to, but not so complex that you can’t think of the answers under pressure. Write it down and put it in your nightstand, or save it in a disguised note on your phone, if need be.

What was your first car? Maybe arrange for a specific wrong answer – like the car they wanted but didn’t have.

How old were you when you fell into the hornet’s nest? Maybe they didn’t fall into a hornet’s nest at all, which is why this question and your pre-arranged answer are good choices.

Don’t use questions that could already be compromised or guessed.

Some people use intentionally “wrong” answers as their key to indicate that the call is legitimate.

This is also sound advice for anyone who receives a call from their workplace IT department instructing them to alter something on their system or network – especially if you are not expecting the call. And yes, even if you “recognize” the caller’s voice.

Verify that the call is legitimate through a secondary method that you initiate.

Depending on the type of “emergency,” another way to determine whether a claimed family emergency is real is to enable some form of family-location tracking service on family members’ devices. There are family locator apps in the major app stores. Be sure to stay mainstream with your selection. Life360 is well-known and works on both iPhones and Android devices, although this is not an endorsement.

Rule 3: Don’t believe your ears. Slow down and stop to assess.

Rule 4: DON’T ANSWER CALLS FROM NUMBERS YOU DON’T RECOGNIZE – EVER!

Why is answering calls from unknown numbers dangerous?

I know someone who used to love to “mess with” solicitors. Guess how the bad guys obtain those 2-15 seconds of your voice? Plus, they can cut and paste your words easily now, making it sound like you agreed to something that you did not.

They call from various numbers. Don’t answer. If you answer, they know they have a live one, and then those calls only get more numerous. They never stop. I block and report every single one as spam. Every time. Every single one.

Do you have voicemail? Remove your voice greeting and use the default one provided by your carrier.

Yes, I sound paranoid, but I’ve been on the receiving end of one of those phone calls, and they are TERRIFYING.

This danger flows both ways.

If you’re a public speaker, your voice is already out there, so you need to communicate clearly with your family NOW so that if they ever receive a middle-of-the-night call “from you,” you’ve already established a safety protocol. If you don’t have one, establish one today.

Additionally, mute your phone and set your notifications to ring-through only for selected phone numbers. This helps control who can reach you. In other words, in the middle of the night, the only numbers that will wake you up are the ones you’ve preselected. That does NOT mean those numbers can’t be spoofed, but it provides you with a layer of protection.

I only have half a dozen ring-through numbers in my phone, and everyone else can wait until morning.

I did this AFTER receiving that terrifying middle-of-the-night phone call, but you can do it now.

Rule 4: Protect yourself by not answering calls from phone numbers you don’t recognize, remove your voice from recordings, and establish your safety routine with your family.

Rule 5: DON’T BELIEVE YOUR EYES EITHER.

Your eyes may betray you.

Be extremely vigilant and highly selective about what you watch and believe. Ask yourself, every time, “Is this image or video real?”

Humans are wired to believe what they hear and see “with their own eyes,” but that metric doesn’t work reliably in today’s world.

Remain on guard and decide each and every time you watch something whether it’s authentic and actually represents what it claims to represent.

If you engage on social media, many of the Reels and TikToks you’ll see now are AI-generated. I can spot them a mile away, but they improve daily, and soon, today’s telltale signs will be gone like last year’s extra fingers, misspelled words, and two left arms.

For example, recently, someone published a pair of side-by-side photos contrasting the same location, supposedly taken several years apart. A then-and-now comparison to make a point. Except that the clouds in the background are distinctive and in exactly the same position in both photos. Yeah, no. One was clearly careless AI. It would have been easy to change the clouds too.

And that was just a bad AI photo, the videos are much more convincing. MUCH.

Google Lens, which allows you to submit photos, is your friend. If Google finds the same or a similar photo attributed to a different time or place, or posted in multiple groups with different claims, you’ve probably uncovered something less than honest.

Rule 5: View everything with suspicion and don’t accept anything you see as authentic without independent verification.

Rule 6: GUARD YOUR HEARTSTRINGS BECAUSE YOUR HEARTSTRINGS ARE CONNECTED TO YOUR PURSESTRINGS.       

Emotional manipulation is a cash cow for the bad guys.

If the story starts out with a kitten or puppy being thrown out on a road and saved, a child being adopted from foster care, a soldier returning home to their dog, or a similar high-drama emotional story – and you’re literally hooked in the first sentence or two – chances are it’s AI.

One clue is that these stories often pique your curiosity and are designed to be highly emotional.

How disappointing is that? We all love happy endings.

Some scams are even more heinous and take advantage of accidents, especially severe ones. The bad guys know that locals monitor local pages and will immediately wonder who is hurt and what happened – especially if their family members aren’t all at home.

AI bots that masquerade as people on social media and entire pages with very interesting names that are entirely AI-driven are very common on Facebook and other social media platforms now. Just this morning, beneath a photo of a local accident, four different bots used exactly the same language: “got this on video. Take a Peep,” with a link, of course. If you read, click, and engage in any way, including liking a post – you’re setting yourself up to be targeted one way or another. This kind of AI-generated content is replacing yesterday’s “copy and paste” scams, although we do still see those from time to time.

On videos or posts, you may be directed to follow a page “for more” or “click a link” (red flag) to find out the ending of the story. Don’t, no matter how much you want to know the ending.

When the purpose is not to steal your credentials or install malware, links may ask you to donate for Fido or Fluffy’s surgery, etc. The ask could be inferred or implied rather than direct and could say that Fido needs surgery by Friday and they still need another $200, or something similar.

This approach doesn’t ask you to contribute, but it makes you think you’d LIKE to contribute to help Fido. Think of this as essentially financial victim grooming using your own compassion and empathy against you.

Worse yet, the link could download malware to your computer, tablet, or phone.

If you have done anything like this, change any password you entered, run an up-to-date antivirus scan, and seek professional help if you suspect malware or tracking software was installed. Also enable 2FA so that a stolen password alone is not enough to access your account.

Yes, I know it’s a pain, but not nearly as big a pain as the alternative.

Aside from the obvious attempts at theft, why do people create these links? I mean, I just want to know what happened to Fluffy.

Here’s what Google’s AI-generated search summary has to say, along with links to the sources it provided.

The really sad part is that truly legitimate organizations suffer because of the level of distrust we must maintain today. If you’re feeling generous, before doing anything, including sharing the story for others to read, check alternate sources about the legitimacy of claims and fundraisers. You don’t want to share and play a part in victimizing your friends.

For example, a few years ago, the Happy Cat Sanctuary burned, killing the owner and many cats. Friends launched a legitimate online fundraising campaign to treat the 150-200 cats that survived the fire. This incident was covered by local news and wasn’t a one-off “sad story” social media plea that couldn’t be verified. I confirmed through local news outlets that the fire occurred when claimed and that the fundraising campaign was legitimate.

If you’ve relented and clicked to watch a reel of some sort, and an ad pops up before the end of the story, or you need to click or follow something, you’ve just taken the bait – so stop right there, spit it out, and realize what makes you vulnerable.

Let’s discuss YouTube, where ads have been part of the platform forever. However, there’s a LOT of AI-generated content on YouTube that is compelling but not authentic.

For example, there’s an AI singer, Michael Bennett, also Mikhail Bennett, with AI-written songs and an AI-generated voice. The combination is very compelling and moving, and it sounds lovely.

Whoever generated that content also took advantage of America’s Got Talent by showing “Michael” competing there with extremely emotional songs. None of that is true. It’s an incredible song that resonated with so many, including me, and the friend who shared it with me, but the video was “over the top,” which was the first red flag. I also noticed the tear never moved on his cheek, and the audience didn’t appear quite “normal.” He also looked “different” in other videos, as though he’s not the same person, but similar. Another AI signal. That’s 2026. By 2027, those telltale signals will probably be gone. Forbes wrote about the fake here.

Remember, if it outrages you, piques your curiosity, or tugs at your heartstrings, that content has probably been generated for exactly that purpose. Don’t click and become a victim.

Rule 6: Guard your heartstrings, and if something seems overly emotional, weird, too much, or just “off,” trust your gut, hold on to your wallet, and verify, verify, verify.

Rule 7 – FLASHING RED NEON SIGNS THAT SAY SLOW DOWN AND STOP. 

Manipulation signals should flash like red neon signs, telling us to put the brakes on.

  • Slow Down
  • Think
  • Stop

Any email, call, text, or other content that creates any of the following reactions should trigger those brakes:

  • A sense of urgency – “If you don’t reset your password by 5 PM, you’ll lose access to…” If you click, you are probably signing into a copycat site that looks exactly like the real one – except it’s stealing your credentials so the bad guys can sign into the real site to steal more than your credentials.
  • Anything frantic – There’s activity on your credit card. “We need you to enter your password here to dispute the charge.” Or, “click here to sign in to see the charge.” Or, “call this number.” This is different from a text I received in my bank’s normal message thread confirming that I had indeed written check number xxx for $xxx.
  • Pressure, direct or implied – “Your subscription has lapsed…click here to renew.” Go to the website and renew – never, ever click, no matter how legitimate the email looks. Full stop!
  • Anything unusual from someone you know. “I’m in a restaurant and in a pickle. I forgot my billfold. Can you please Venmo me $50 so I can pay my bill?” Call them using the phone number that you already have. Do NOT reply to the text or click to call that number.
  • Manipulative instructions – “We’ve received your order. The file is attached.” This is especially effective if you HAVEN’T ordered anything because it generates both curiosity and concern. Do not, under any circumstances, click on an attachment you’re not expecting. Slam on your mental brakes!

This KnowBe4 alert arrived today and demonstrates several flashing red neon signs at once.

This scam arrives as a Facebook Messenger message masquerading as Facebook, or Meta itself. The message even includes an accurate logo, but it is not legitimate. Red flags include the concern it generates, an unexpected PDF attachment, a threat of imminent account deletion, and the sender’s name is one letter off. In the message, “verified” is spelled “verrifed,” with two Rs, but if you’re focused on the words “permanently deleted,” you’ll never notice that. You may be panicked and not thinking clearly. That’s exactly what they are counting on.

Although there are often no misspelled words in scam emails today, in this case, the misspelled username is your first clue. Two of my friends received this through Messenger today, reported it, and an hour or so later, I received the notification from KnowBe4.

The bad guys trick you by making you feel that the action is:

  • Completely safe – because it came from someplace or someone you routinely communicate or do business with (but it really didn’t and the bad guys are trying to trick you).
  • Urgent – someone is trying to compromise your account, and you need to <fill in the blank> right away (except complying compromises your security).
  • Required to avoid negative consequences – if you don’t finish this training by Monday morning, you’ll no longer have access to your accounts (except it’s a fraud, trying to get you to sign in through a very convincing authentic-looking but malicious portal).

In any of these types of situations, don’t comply or reply, and never return calls to any number they give you. Find the number on the back of your credit card, for example, or sign into the site you’re already familiar with to take care of business.

Always ask yourself:

  • Is this normal?
  • Does it feel “off”?
  • Why?
  • What am I giving away? It’s not always money. Your information is gold, too.

Rule 7: Slow down, stop, and evaluate. A sense of urgency is a flashing red neon sign designed to stop you from thinking.

Rule 8 – STOP RANDOMLY ENGAGING AND LOCK DOWN SOCIAL MEDIA.

Algorithms control what you see.

Worse yet, once you click or even expand to read, the social media algorithms send you more of the same, which is the exact intention of the creators. The phenomenon is often referred to as a social media bubble or echo chamber because it reinforces what you believe based on what you’re seeing and continue to see.

It used to be that ugly political content was restricted to election cycles, but not anymore. It’s regular daily fodder and can easily be manipulated. The key, however, is that whatever you watch or read, you’ll see more of it in your social media feed.

Another effect of reading one of those scammy but very interesting and engaging stories is that Facebook now uses AI (how ironic, right) to show you more of the same. It’s a never-ending cycle.

One time I accidentally clicked to watch a reel, and it took days of clicking on the little “X” in the upper right-hand corner of the videos (or the posts) to signal to Facebook that I really didn’t want to see anything else like that. Hint – this works with ads too.

It’s fine to read that fun public story – but you don’t have to engage by clicking and liking. Clicking DOESN’T DO ANYTHING FOR YOU, but it does provide information about you to other people, including AI bots and the social media platform itself.

If you ever “like” or comment on a public post on social media, your reaction is visible to everyone, including AI bots, and you’ve given them information about yourself that they can use to target you more effectively. Just stop.

Don’t expose any more of your personal information than is already out there – and you might be surprised just how much there actually is.

Do you use your real name? Is your birth year, or much worse yet, your complete birth date displayed in your public profile? If so, remove it.

Do yourself a favor.

  • Google your name with your state.
  • Google your phone number.
  • Google your email address.

Your information doesn’t even need to be on the dark web for someone to find very revealing data about you.

You can discover even more about yourself, or anyone else, by checking out BeenVerified.

Record aggregators such as BeenVerified also provide the names of people who live or have lived with you and with whom you’re associated. In other words, your family members.

It’s so easy to unintentionally feed the data-gathering machine.

Ancestry includes voter-registration lists, where available, complete with full names, addresses, birth dates, and other personal information through 2023.

Protect yourself, where possible, and never publicly display your birth date or year on any platform. Do note that this information can be part of recovering your account, should it become compromised, so if you include that information, privatize it.

Are you on LinkedIn? That’s another avenue for information gathering, including your employer.

There’s not much you can do about information that’s already out there, but you can stop providing more through social media.

I wrote the article titled STOP, THINK, & RUN – Stop Innocently Giving Your Information to Cybercrooks on Social Media, which explains how to lock your accounts down, and why you should.

Rule 8: Lock your social media accounts down and zip your lip.

Rule 9: LEARN THE NEW THREAT LANDSCAPE

The threat landscape has not improved for us, that’s for sure. The crooks have gotten smarter and much more effective with their AI assistants.

Yesterday’s Nigerian princes, those handsome widower generals in uniform, and buxom young women randomly targeting people who comment on public posts on social media are somehow almost all gone, although not entirely. They’ve been replaced by something much more dangerous. AI makes everything easier – including crime.

Now, the criminal’s objective is to get you to take an action that isn’t in your best interest.

AI makes both impersonation and personalization much easier and more convincing, and attacks may now involve multiple methods in tandem.

The most convincing attacks use two channels. For example, they both email and call you, which makes the communication seem more legitimate, which in turn makes you feel more secure. They may claim that your credit card has been compromised or begin with, “This is your bank…”

Worse yet, you really can’t tell and may have no way of knowing whether the communication is legitimate, so you go ahead and click because you’re tired and “it’s probably fine,” except it’s not.

The bad actors may have already compromised your system or phone if you clicked on something you shouldn’t have, and they are just waiting to exploit it by capturing your login information – including your password.

They may have been monitoring your communications for some time now, not just waiting for any opportunity, but an exceptional, highly profitable opportunity.

Never use a “call back” button, telephone number, or link supplied in the message. Call the bank or whomever directly at a number you can confirm, or use another form of communication – like walking in the door.

I was at the bank in person recently, and they are now warning people about scams before they transfer money on your behalf. You are required to click to acknowledge that you read the scam warning signs they provided. The bank was also reminding people that debit cards are a “direct siphon into your bank account” and someone can easily drain it if your card or PIN is compromised.

If someone fraudulently charges something to your credit card, you can dispute it, but if they empty your bank or retirement account, the money may be difficult or more likely impossible to recover. Report any suspicious activity to your financial institution IMMEDIATELY, regardless of the hour, because the outcome may depend partly on how quickly you report it.

Rule 9: Learn the new threat landscape and keep current.

Rule 10: NEVER UPLOAD ANYTHING WITH PRIVATE INFORMATION, INCLUDING NAMES – YOURS OR OTHER PEOPLE’S.

This includes uploading your monthly budget worksheet to AI, your tax information, your DNA match list with other people’s names from a DNA testing site, etc.

Genetic genealogists, I’m looking at you here. If the data isn’t already in the public domain, DO NOT UPLOAD IT to AI agents.

Your browser will not protect you, and neither will a VPN. I’ve had people tell me that both of these will protect what you upload when using AI. They don’t. Neither prevents an AI service from receiving information that you intentionally upload to it.

Don’t fall for companies that encourage you to “upload your DNA file” for “better” information or to learn how you match ancient specimens. Check credible sources that are well-known and respected in this industry, such as my blog, Diahan Southard at Your DNA Guide, or the Genetic Genealogy Tips and Techniques Group on Facebook. If you discover that none of us, meaning me, Diahan, or the administrators of that Facebook group are recommending a company, pause to ask yourself why.

When considering an upload, ask yourself:

  • Who are those people, anyway?
  • Where are they located?
  • What are their credentials?
  • What are they doing with your autosomal DNA file?

If you’re thinking about uploading your DNA or matches to an AI tool or to a company you know nothing about merely because it “sounds good,” just don’t.

If you’re going to err, err on the side of extreme caution because once your DNA is “out there” and exposed, you can’t just take it back like it never happened.

Rule 10: Never upload your own private information to AI or any other service that you have not thoroughly vetted, and don’t upload your match information or anyone else’s private information without their specific permission.

In Summary

I chose to address AI’s dangers after first exploring its benefits in the earlier articles because I don’t want you to think I don’t like AI. I absolutely do. I use AI in some form every day.

However, AI can also be extremely dangerous, especially for the unwary. I cannot emphasize this enough.

AI will become more advanced and “better,” which means we, as consumers, have to be even more vigilant. While the idea behind “Who are you going to believe, me or your lying eyes?” was once a Marx Brothers punch line, and “Lyin’ Eyes” later became an Eagles song, today that warning pertains to AI and social media, both separately and together.

I want you to stay safe. AI is one of the tools that we, as genealogists, can use quite successfully under some circumstances. Just don’t get out over your skis.

To recap:

  • Don’t click
  • Don’t believe your ears, or eyes either
  • Never save important passwords in your browser
  • Guard your heartstrings
  • Remain vigilant
  • Slow down, stop and assess
  • Verify independently
  • Protect yourself
  • Put a family protocol in place
  • Stop randomly engaging and lock down social media
  • Guard what cannot be recovered
  • Don’t upload private information without thoroughly vetting the service
  • Never upload other people’s private information without their permission
  • Educate yourself and stay current

While the specifics of each platform change quickly, the underlying fundamentals of safety and increased vigilance will remain constant.

As mentioned in the third AI article, follow Mark Thompson and Steve Little, the Family History AI guys, for updates.

Stay safe and enjoy the ever-evolving world of AI.

But remember…

Always, always be suspicious. You may only get to be wrong once.

_____________________________________________________________

Share the Love!

You’re always welcome to forward articles or links to friends and share on social media.

Subscribe!

If you haven’t already subscribed, it’s free. You’ll receive an e-mail whenever I publish by clicking the “follow” button at the top of the main blog page, here.

Help Keep This Blog Free

I receive a small commission when you click a vendor link in my articles and purchase that item. This does NOT increase your price but helps me keep the lights on and this informational blog free for everyone. Please click on the affiliate links in the articles or to the vendors below if you are purchasing products or DNA testing.

Thank you so much.

DNA Purchases and Free Uploads

Genealogy Products and Services

My Books

Genealogy Books

Genealogy Research

What’s Changed? –  Autosomal DNA Vendor Feature Changes Since the 23andMe Data Compromise

The 23andMe customer data compromise has reverberated throughout the technology industry, not limited to DNA testing.

The 23andMe compromise has provided the impetus for reflection and security and policy reviews at each DNA testing vendor.

That’s a good thing.

What has been and remains challenging is keeping track of which features have been disabled and are no longer available at each vendor as the vendors, including 23andMe, attempt to right themselves from this blow. Unfortunately, or maybe fortunately, we can’t just return to “business as usual.”

Some of these feature removals may only be paused, and a few have already returned. Some may never be resumed.

We don’t really know yet.

If you’re having trouble keeping track, welcome to the club.

The features that have been disabled are features that were exploited at 23andMe or could have been exploited by bad actors who signed on “as you,” exposing not only your data but that of your matches in one way or another.

To be very clear, there was no data leak or compromise at any other vendor, but some other vendors provide(d) similar features for their customers. Every vendor offering DNA testing to genealogists had to stop, pause, and reevaluate their security measures. That’s exactly what they should have done. Genetic genealogy is a team sport where compromising one person’s account exposes at least some information about thousands more individuals.

Every company has proceeded somewhat differently based on how their features work.

I’ve compiled a chart listing the four primary vendors alphabetically, with affected features.

The Scorecard

In this chart, “Not available” means the feature was available before the 23andMe incident but is not currently available.

Feature 23andMe Ancestry FamilyTreeDNA MyHeritage
Two-factor Authentication (2FA)[1] Required Required Will be required for project administrators and available for all users[2] Will be required soon.
Forced Password Reset Yes No May be required for project administrators. Yes
Match information download[3] Not available Never was available Not available until after 2FA implementation Not available
Matching segment download[4] Not available Never was available Not available until after 2FA implementation Not available
Shared matches[5] Not available Available[6] Available Available
Shared matches who match each other Not available Never was available Available thru Matrix, but not segments Partially available through triangulation
Shared matches match segments Not available Never was available Never was available Never was available
Shared matches relationship to each other Not available Never was available Never was available Predicted available
Triangulation Not available Never was available Available[7] Available
Chromosome Browser Not available Never was available Available Available
Daily matching or browse rate limited[8] No No No Yes
Shared ethnicity with matches[9] Not available Available Available by opt-in Not available
Filter matches by ethnicity Never was available Never was available Never was available Not available

 

Accepts 23andMe DNA file uploads Not applicable Never was available Paused Not restricted but not available because 23andMe does not currently allow the download of your raw data file

Other features remain unchanged, so they are not mentioned.

I think I accounted for everything that has changed, including some features already resumed at MyHeritage.

23andMe has not stated if or when they will return any of the functionality that has been removed.

FamilyTreeDNA plans to return their paused features after 2FA has been implemented in early 2024.

Please note that this information may change at any time.

_____________________________________________________________

Follow DNAexplain on Facebook, here.

Share the Love!

You’re always welcome to forward articles or links to friends and share on social media.

If you haven’t already subscribed (it’s free,) you can receive an email whenever I publish by clicking the “follow” button on the main blog page, here.

You Can Help Keep This Blog Free

I receive a small contribution when you click on some of the links to vendors in my articles. This does NOT increase your price but helps me keep the lights on and this informational blog free for everyone. Please click on the links in the articles or to the vendors below if you are purchasing products or DNA testing.

Thank you so much.

DNA Purchases and Free Uploads

Genealogy Products and Services

My Book

Genealogy Books

Genealogy Research

[1] There has been a great deal of gnashing of teeth surrounding 2FA and how it’s implemented at each vendor. If you experience issues, please contact the vendor in question.

[2] At FamilyTreeDNA, testers utilize a kit number as their username, not their name or email. No place is the kit number publicly associated with the user’s name. In the 23andMe breach, the user’s email and passwords had been exposed in earlier breaches, so the hacker simply tried the same username and password at 23andMe, with great success. That scenario cannot occur at FamilyTreeDNA because the username is not their email address, which is why 2FA is not required for users. Administrators can select their username, so they will be required to utilize 2FA soon.

[3] This means information about your DNA matches other than your matching segments, such as email address, maternal or paternal matches, notes, surnames, and other relevant information.

[4] Matching segment information for each match. Used for triangulation, ancestor identification, and at DNAPainter.

[5] Shared matches between you and another match.

[6] Ancestry has recently announced that they will require a membership to view several features available with a DNA test, including Common Ancestors (ThruLines), Notes, Trees, Groups, and filtering matches by unviewed status. These features will not be available to DNA testers without an Ancestry subscription.

[7] Available if maternal/paternal matching is enabled. When matching, each individual who matches the tester and other testers and is bucketed on the same maternal/paternal side will triangulate on at least one segment.

[8] This is to prevent data scraping if a bad actor gains access to your account.

[9] The 23andMe data was reported to have focused on both Jewish and Chinese customers

23andMe: DNA Relatives, Connections, Event History Report and Other Security Tools

A few days ago, I suggested a pause strategy while you ponder whether or not you wanted to delete your DNA file in light of the recent data exposure at 23andMe. I need to revise this with additional information today.

First and foremost, disabling DNA Relatives does NOT remove all matching. You need to remove Connections separately.

Secondarily, there’s a report at 23andMe for you to order to determine whether your account may have been individually compromised. I’ve described how to find it and use the information in the report.

This article includes several sections with important information about how these intertwined features at 23andMe work and instructions to protect yourself.

  • An update on the breach situation with informational links
  • Customer notifications
  • Confusion regarding types of sharing – DNA Relatives vs Connections
  • Explaining the difference between DNA Relatives and Connections
  • Step-by-step instructions for removing Connections – disabling DNA Relatives doesn’t accomplish this or stop matching/linkage to Connections
  • Who sees what, when?
  • DNA Relatives and Connections comparison chart
  • Account Event History – how to determine when your account was signed into, from where, what they (or you) did, and when
  • Deletion instructions and caveats
  • Summary

Update on Breach Information

I’m not going to post anything from the hacker(s) – but please, in an abundance of caution, presume your data is now available publicly or will be when the hacker sells the balance of the accounts they have and act accordingly.

The hacker has posted millions of accounts already, and I know people who have found themselves in the “sample” download provided by the hacker to convince people that the breach and resulting data is for real. If you really want to see this for yourself, the hacker, Golem, is very active at BreachForums, under Leaks, 23andMe – but I DO NOT recommend hanging out there. I reached out to colleagues who work with security and breach monitoring services. I am not poking around myself.

This 23andMe customer information first appeared in August, not October, when a hacker by a different name on Hydra posted images of the accounts of both Sergey Brin and Anne Wojcicki, CEO of 23andMe and her former husband, CEO of Google. The hacker said that the information was obtained through an API provided by 23andMe to pharmaceutical companies. Additionally, the hacker said they had already sold all of that initial data to “an individual in Iran.” You can read about this here.

Furthermore, if what the hacker or hackers say is accurate, this situation is far more serious than a password recycling issue. I don’t want to speculate because I can’t verify, although many people have written to me to say two things:

  • They were seeing leaked customer information weeks earlier
  • They did use a unique password at 23andMe

Here are four additional articles that I suggest reading to understand the scope of the situation and why there’s so much uncertainty:

One of my blog readers asked why anyone would want to do this. Of course, there can be many or even multiple motivations, but based on some of the commentary, it appears that Jewish people were targeted and compiled identifying data sold to Iran who backs Hamas. If you’re a Jewish person, anyplace in the world, you have to be extremely concerned especially since this test identifies your closest relatives and (if provided) the location where you live.

Both 23andMe and Ancestry display your current location if provided and selected. I NEVER recommend doing that under any circumstances. Of course, if the hacker gained access to individual accounts as reported and you entered that information, even if you didn’t choose to share it, they have it anyway.

Customer Notification

Please note that so far, the only notifications received by 23andMe customers say that their information was revealed through DNA relatives, meaning that at least one of their matches’ accounts was compromised. No one, to my knowledge, has received a notification that their own account has been directly compromised. Perhaps 23andMe doesn’t know whose accounts were compromised yet.

Near the end of this article, I’ll show you how to obtain a list of all the activity that has taken place on your 23andMe account so you can see if there are logins from locations not your own or other suspicious activity.

According to the original announcements from 23andMe and others, the data exposure was a result of two things:

  • Direct access to accounts due to reused passwords allowing the hacker to aggregate data and sign in as the user. You can see if your email address has been found in a data breach at the site, haveibeen pwned.com. I know this list is incomplete, though, because I’ve been notified by letter by other companies not listed here.
  • DNA Relatives information shows DNA matches, segments, and your matches’ potential relationships to each other along with their shared data, permitting triangulation.

The more I read about this from credible sources, combined with how 23andMe has handled this situation, the more “uncomfortable” I become.

Before 23andMe even straightened this mess out, this week, they introduced a new “Total Health” subscription for the low price of $99 PER MONTH. Seriously. Billed as one payment of $1,188 per year. To me, this smacks of a company desperate for money.

How do we even begin to place any confidence in this service, given what has already been exposed and the unanswered questions? Especially given that for weeks, 23andMe dismissively replied to customers who informed them of the issue that their systems had not been accessed in an unauthorized manner. Not to mention, this announcement is entirely tone-deaf as we struggle to deal with what has already been exposed one way or another.

In response to this, if you still want to maintain your existing account at 23andMe, I have help for you. If you want to delete it, I’ve provided instructions for that too.

Questions and Challenges

I discovered that DNA Relatives and Connections don’t work in exactly the way I believed they did, and it’s very confusing. Nothing, not one thing that 23andme has provided has addressed exactly what information has been exposed or what customers can do other than change their password and add 2FA.

  • Was the breach only DNA Relatives, or was it Connections, too?
  • Connections is essentially a subset of DNA Relatives plus potentially some unrelated people.
  • Not everyone has DNA Relatives enabled, but if not, Connections still exposes/exposed you if your account was individually breached.
  • 23andMe only mentioned DNA Relatives, so you may think you’re in the clear if you don’t have DNA Relatives enabled. That’s inaccurate if you have any Connections and your account was individually breached.
  • If the hacker did sign on to your account, Connections are equally vulnerable.
  • The hacker could enable DNA Relatives without your knowledge to create a more lucrative fishing environment. I’ve provided instructions for how to determine if this might have happened.

Disabling DNA Relatives is not enough.

23andMe Sharing Options Are Confusing

I first reported the breach here and said in my article, here, that a pause strategy would be to stop sharing in DNA Relatives, which would effectively provide you with time to make a decision.

I knew that DNA Relatives did not unilaterally disable Connections, but I did NOT realize how much information your Connections can see.

Over the years, 23andMe has revised how their sharing works. I remember when DNA Relatives opt-in and opt-out was added in 2014. It was extremely confusing then and still is.

DNA Relatives and Connections are confusing individually and together. I could not find any feature comparison or side-by-side table for each tool, either individually,  compared to each other, or with both enabled.

Because of this confusion, what we need right now is a one-button invisibility cloak that we can click to JUST STOP being visible to everyone until we reverse the invisibility cloak by opting in again – without losing anything or being penalized.

That’s what most people think happens when you stop sharing through DNA Relatives, but it’s not.

There is no invisibility cloak at 23andMe like there is at other vendors.

No Invisibility Cloak

I spent a considerable amount of time over the past few days trying to figure out the differences between DNA Relatives and Connections.

Believe it or not, that information was almost impossible to find, as it was scattered piecemeal across several places.

Let me step you through where to find it, and then compile an easy reference.

If you sign on to your account, you can see on the left-hand side that you have several selections under DNA Relatives.

Under Connections, you have the statuses of Connected, Pending, and Not Connected.

If you mouse over Connections, you see a general description.

I have two separate tests at 23andMe, and I have DNA Relatives enabled on one of the tests and disabled on the other, so I can see the differences when compared to the same people.

I have 1803 DNA Relatives, meaning matches, but the connections option told me that 348 were also Connections.

Why Do I Have 348 Connections?

Remember that 23andMe limits your matches to 1500, and the lowest matches roll off your match list without a subscription, which was only introduced in the last year or so. The subscription only allows 5,000 matches before the matches roll off your match list.

The only way to prevent matches from rolling off your list was/is to “Connect” with them, either through DNA relatives or initiating messaging. So, for years, genealogists sent a connection request to every match they had, beginning with the smallest first, in order to preserve matches that would otherwise be gone. That’s why I have 1803 matches and not just 1500 like I do on the second account where I have not established “Connections.”

Given my number of matches at the other DNA testing companies, I would likely have well over 20,000 matches, so preserving as much as possible was important to genealogists.

Understanding Connections

I switched to a different account that I manage that opted out of DNA matching a decade ago, but has more Connections than I do with many of the same people that I match.

You can view your DNA Connections by clicking on Family & Friends and then on Your Connections.

As you can see on the left, you can either share “Ancestry” with these Connections, which means typical genealogy info, or “Health + Ancestry.” Relevant to the breach, your Ancestry Composition (ethnicity) results as compared to your Connections (and DNA Relatives) are shown.

You can invite anyone to connect with you, including people on your match list or anyone else you know who has tested. In other words, your spouse or a cousin whom you DON’T MATCH.

Here’s an example of a cousin by marriage who I’ve known for years. We connected even though we don’t match and are only related by marriage.

Some Connection invitations that you receive or send are for Ancestry only, and other invitations are for BOTH Ancestry and Health.

Melissa sent me a combined request for both Ancestry and Health.

Remember that the focus of 23andMe has always been medicine, big pharma and health. Unfortunately, 23andMe PRECHECKS to accept the Health sharing option when you’ve been invited to share Health. It’s easy to miss, so UNCHECK Health if you don’t want to share YOUR HEALTH INFORMATION. The only people I’ve ever shared Health with are my immediate family members.

What’s Different?

I wanted to know what information was different about someone you’re NOT connected with and someone you’re connected with.

One of my DNA matches, Gwen, requested a Connection. Here’s the information I can see with Gwen before her Connection request.

I verified that this information is accurate by comparing Connections requests with a family member who is opted into DNA Relatives, one who is not, and also with my research-buddy cousin who is a Connection but not a match.

Any one person can potentially be:

  • A DNA Relative and not a Connection
  • A Connection and not a DNA Relative
  • A Connection but not participating in DNA Relatives even though they are a match

Today, the information a Connection and a DNA Relative can see since 23andMe disabled some DNA Relatives features seems identical.

Gwen’s profile card shows her name, location where she lives, and year of birth, if provided and selected for display. She obviously did not allow her birth year to be displayed, but she did allow the city/state where she lives.

23andMe estimates how I may be related to Gwen and how much DNA we share..

Gwen’s family background, which I’ve blurred. I have removed my information as I ponder whether to delete my account or not.

Ancestry Composition (ethnicity) of both people. Note that even if DNA Relatives is not enabled, either person’s account can view the shared ethnicity of both accounts.

Amounts of Neanderthal Ancestry.

How Sharing Works

23andMe discussed sharing, but differentiating between DNA Relatives and Connections is unclear.

Based on my comparison and their descriptions, I think I’ve figured out the differences. Let’s begin with their description of how sharing works.

Here, they describe part of what Connections shows.

At this point, the features of DNA Relatives that were available IN ADDITION to what could be viewed in Connections have been disabled due to the breach.

The next image is part of the Connections section, followed by DNA Relatives,

I was surprised that Shared DNA was displayed using Connections alone, before 23andMe (possibly temporarily) disabled this functionality in response to the breach. I would have presumed that if you disabled DNA Relatives, your DNA would NOT have been shown to your DNA relatives.

DNA Relatives was necessary for advanced features, including viewing relationships between your matches, meaning you and two other people, and also between your matches and each other. That means you could compare them to each other.

That feature selection is now gone as well. For the record, this graphic was out of date anyway, but now it doesn’t matter.

Connections DOES have access to the tree calculated by 23andMe but (apparently) only for people you are connected with unless you have DNA Relatives enabled. Please note that all accounts managed by one person appear to be connected to each other, although that might not be universal. I manage four kits, and all of them are shown as connections to each other.

Considerations provided by 23andMe

Here’s what they don’t say.

Disabling Your DNA Relatives Option does NOT Change Connections

This is very important considering how much information Connections can view:

  • Disabling DNA Relatives does NOT disable sharing. You can disable DNA Relatives across the board with one setting, but you CANNOT do that with Connections.
  • Each Connection must be deleted individually.

After you disable DNA Relatives, as I described in this article, under the heading, “Opting Out of DNA Relatives” you need to additionally remove each Connection if you genuinely don’t want to be seen by other people as a match. If you DO want to be seen as a match, then don’t disable DNA Relatives.

DNA Relatives will eliminate new matches from automatically occurring but won’t remove anyone you’ve previously added as a Connection.

To view and edit your connections, select “Your Connections” under “Family and Friends.”

For each Connection, click on the gear, then select which type of sharing to remove.

Please note that you may have to refresh the page to reload Connections, as there is no “load more” button, until you see the message, “You aren’t connected with anyone yet.”

Connections Versus DNA Relatives Chart

If you’ve had a hard time keeping this straight, me too. I created a chart that lists each feature and if it’s present in DNA Relatives, Connections, or both.

Feature Connections Only DNA Relatives Comment
Profile Yes Yes
Current Location, Year of Birth, Genetic Sex Yes Yes If provided and selected for display
Additional info about yourself Yes Yes If provided
Prevents Rolling Off Match List at Threshold Yes No Only Connections or people you’ve initiated contact with are retained
Matches Yes, only Connections Yes
Non-Relatives Can send an invitation to people you’re not biologically related to meaning not on your match list No, only DNA matches
Ancestry Yes Yes, plus shared matches and additional information If selected
Health If selected If selected
Genetic Relationship Yes Yes Estimated
Shared DNA Percent Yes Yes
Genetic Constructed Family Tree Connections only Yes all To about 4th generation shared ancestors
Family Background – birth places of grandparents Yes Yes
Other ancestors’ birthplace Yes Yes
External Family Tree Link Yes Yes If provided
Ancestry Composition (ethnicity) Yes Yes
Shared ethnicity Yes Yes
Maternal, Paternal Haplogroups Yes Yes Base to mid-level
Neanderthal Ancestry Yes Yes
Matching segments Shown in 23andMe documentation, currently disabled Yes, currently disabled Disabled due to breach
Chromosome browser Not shown in 23andMe documentation Yes, currently disabled Disabled due to breach
Shared matches No Yes, currently disabled Disabled due to breach
Triangulation No Was changed recently to be more difficult, now disabled Disabled due to breach
Shared Matches compared to each other’s tests No Yes, currently disabled Disabled due to breach
Shared Matches relationships to each other No Yes, currently disabled Disabled due to breach
Download Matches I don’t think so, but I can’t positively confirm Yes, currently disabled Disabled due to breach
Download Segment information No Yes, currently disabled Disabled due to breach
Download Raw data file (Your own) Yes Yes

Now that you know what can be seen and done and by whom, let’s take a look at how your account has been accessed.

Account Event History – Who Signed In To Your Account?

There’s a little-known feature at 23andMe that you can utilize to view the locations of sign-ins to your account and what was done, including changes and file download requests.

Navigate to settings.

Scroll down to “23andMe Data,” then click on View.

Scroll to profile data, click on “Account Event History,” then “Request Download.” 23andMe says it may take several days, but mine was ready the following day. You’ll receive a link to sign in and download a spreadsheet. Click on the blue “Account Event History” to download the report.

At the top, you’ll see column names. Please note that I added the Location column to record the results of the “Client IP Addr” lookup.

The “Client IP Addr” field is a record of where the login was initiated from. It’s your electronic address, or more specifically, the address of your internet provider, and it may not be the exact town where you live, but someplace close. I’ve blurred mine, but not where failed logins originated.

I use this site or this site to identify IP address sources.

As you can see, on May 1, 7, and 10, someone tried to sign in with my email address. It wasn’t me or the region where I live, and I was not traveling.

I was able to track these IP addresses to cities but not to individuals, of course. One tracked to a specific Internet Service Provider in that city, but nothing more.

However, that tells me that someone tried three times to use what was probably a compromised password. Thank goodness I don’t reuse passwords.

I also need to mention that you can find legitimate differences in location. For example, if you are traveling or use tools like Genetic Affairs that sign on on your behalf from their location, the IP address will reflect connection services from those locations.

You will also see interesting IP addresses, like that 127 address. That means the host computer made the change. In essence, that means that another 23andMe user removed sharing with me. That’s clearly legitimate.

I did not see any successful sign-ins from unauthorized locations. If you see a successful sign-in from an unknown location that’s not close to your home sometime in 2022 or 2023, and you weren’t traveling, nor using a location masking tool like TOR, then please notify 23andMe immediately.

The notification email I received from 23andMe was that my information had been exposed through DNA Relatives. Based on their notification in addition to the information in my report, my personal account does not appear to be individually breached.

23andMe clearly has access to this IP address information for all users, so I’m really surprised that they have not notified anyone, at least not that I know of, that their accounts have been DIRECTLY compromised – meaning NOT through DNA Relatives. Even if someone signed on using the correct password, there could/should be some pattern of sign-ons through not-normal locations for a group of customers during this time.

Of course, if the hacker was telling the truth and the breach was NOT through password reuse (stuffing,) and was through an API, neither users nor 23andMe may see unauthorized account accesses. I hope 23andMe and the professionals they have retained are able to sniff out the difference and will update their customers soon.

Regardless, I recommend requesting and reviewing this report and implementing 2FA everyplace that you can.

Deleting Your Profile

Based on your comfort level, you may decide to delete your test at 23andMe. It’s a personal decision that everyone has to make for themselves. There is no universally right or wrong decision, and I’m not recommending either way.

Before I show how to delete your data, be aware that IF YOU MANAGE MULTIPLE PROFILES, YOU NEED TO CONTACT CUSTOMER CARE UNLESS YOU WANT TO DELETE ALL THE PROFILES.

  • If you want to delete only your profile, you can transfer other profiles under your care to someone else.
  • If you manage multiple profiles and click delete, all of the profiles you manage will be deleted.

To find the delete function, click on the down arrow by your initials at top right, then on Settings.

Scroll to the very bottom.

Click on “View,” then scroll to the bottom to the Delete Data section.

23andMe provides links in this section to review, so please do. This includes information about how to transfer profiles and things to consider.

If you want to download your raw DNA file to use as an upload to other vendors, be sure to do it before you delete, because it won’t be available after. You can find instructions, here.

Remember, delete is permanent, and you’ll need to pay to retest if you change your mind.

In Summary

I hope this information has helped organize and explain things in a logical manner.

To recap, to become totally invisible, meaning no other tester can see you:

  • Disable DNA Relatives
  • Delete Connections individually and selectively

If you delete connections and those matches are lower than your 1,500th match, they will roll off your match list unless you have a subscription, and then it’s 5,000.

Additional Tasks

  • Request your Account Event History and review for anomalies.
  • For security purposes, change your password to one you have not used elsewhere, if you have not already, and enable 2FA.

I hope that 23andMe has or will take care of whatever issues they have, post haste, and will be transparent about what actually happened. I also hope they will find a way to re-enable the tools that have been disabled. That functionality is critically important to genealogists, and without those tools and the lack of trees, there’s little reason for genealogists to test at 23andMe.

We can’t change what has already happened. Each one of us has to decide whether we want our test to remain at 23andMe and, if so, what steps we want to take to move forward successfully.

I hope this information helps you decide how to handle the situation and perhaps relieve some anxiety. Now you know how to check your activity report, understand who sees what in DNA Relatives and Connections, associated options, what needs to be done, and how to take appropriate action.

Other Vendors

You probably have observed and will continue to see other vendors implementing additional security measures, such as required 2FA, precautions against account scraping, and not accepting uploads from 23andMe in case the hacker downloaded DNA files.

These revisions may be temporary or permanent, or some of each. I’m grateful for each vendor taking steps to protect our information from unauthorized access. I’ll write more after things settle down and we better understand the new landscape.

_____________________________________________________________

Follow DNAexplain on Facebook, here.

Share the Love!

You’re always welcome to forward articles or links to friends and share on social media.

If you haven’t already subscribed (it’s free,) you can receive an email whenever I publish by clicking the “follow” button on the main blog page, here.

You Can Help Keep This Blog Free

I receive a small contribution when you click on some of the links to vendors in my articles. This does NOT increase the price you pay but helps me to keep the lights on and this informational blog free for everyone. Please click on the links in the articles or to the vendors below if you are purchasing products or DNA testing.

Thank you so much.

DNA Purchases and Free Uploads

Genealogy Products and Services

My Book

Genealogy Books

  • com – Lots of wonderful genealogy research books
  • American Ancestors – Wonderful selection of genealogy books

Genealogy Research

The 23andMe Data Exposure – New Info, Considerations and A Pause Strategy

As most of you know, 23andMe has been suffering the effects of what appears to be a significant data compromise, meaning many of their customers’ information has been compromised or exposed.

Here’s the latest news indicating that information from millions more accounts has been offered on the dark web, along with 23andMe’s latest update, here.

I’ve been trying to keep up with the changes, and I must tell you, the hacker’s quotes in that Cybernews article chill me to the bone.

Furthermore, the depth of this issue is still unfolding, with a report of an earlier August breach.

What Has Happened

Essentially, due to users who have reused and recycled passwords, a bad actor was able to sign on to many customer’s accounts, directly, acting “as” the customer, which allowed them to:

  • View (or change) personal information
  • View matches’ information
  • View matches in common
  • View triangulation information
  • View how your matches also match each other
  • View health information if you and your match have agreed to share at that level
  • View ethnicity, shared ethnicity, and ethnicity chromosome painting
  • View the family tree provided by 23andMe that provides an estimated reconstruction of your matches to you and each other to ancestors several generations into the past
  • View your profile information
  • Download your matches
  • Download your raw data file

Anything you can do or see, they could do or see because they were signed on as “you.”

That’s a lot, and I’m sure that 23andMe is struggling with how to keep their customers safe, especially since this data compromise was reportedly not due to a breach or “break-in” of their system or site, but due to social engineering failures. It’s also difficult to sort the truth from the rest.

Right now, things are moving so fast on this front that every time I have an article ready to publish, something else changes. I’m going to share what I do know, and what you can do.

Some Users Have Been Notified

I know of at least two people who have been notified by 23andMe that their data was exposed in the compromise, receiving the same email. The communication was nonspecific, partially extracted as follows.

After further review, we have identified your DNA Relatives profile as one that was impacted in this incident. Specifically, there was unauthorized access to one or more 23andMe accounts that were connected to you through DNA Relatives. As a result, the DNA Relatives profile information you provided in this feature was exposed to the threat actor.

Based on our investigation so far, we believe only your DNA Relatives profile attributes were exposed.

They did not say, nor do I know how 23andMe identified those customers.

This only applies to people whose information was partially exposed as a match to a compromised account. I don’t know if they have identified the compromised accounts and are notifying those people, too.

Given the reported magnitude of this exposure, I wonder why only two people have mentioned being informed. None of my accounts have been informed, nor those of family members.

Using Email as a User ID

Using an email address as half of your user ID essentially gives that piece of the puzzle away.

It makes users particularly vulnerable because bad actors only have to obtain the second half – a password. That’s a lot easier than you’d think.

If nothing else, this 23andMe incident illustrates just how many people engage in unsafe security practices.

Not all vendors utilize email as part of your user id, and those that do often utilize other safety practices, including but not limited to two-factor authentication (2FA.)

Forced Password Reset

Several days ago, 23andMe forced their customers to reset their passwords before signing in. Of course, by that time, millions of cows had already left the proverbial barn. Still, that was certainly the responsible thing for 23andMe to do, preventing additional damage, assuming their customers didn’t reuse yet another password.

I finally managed to reset my password, although that was anything but easy. In order to do a password reset, the standard procedure and the one 23andMe follows, is to send a reset link or key to your email address on file. However, if you changed your email, or it has been “blacklisted” because your carrier was down at some point when 23andMe tried to communicate with you, or the reset email wasn’t received for some other reason, you have to contact support to obtain assistance. Needless to say, 23andMe support is overwhelmed at this point.

23andMe has provided a Privacy and Security page, with suggestions, here.

Two-Factor Authentication

23andMe has NOT required their customers to implement two-factor authentication, known as 2FA.

They DO provide an option to enable 2FA, and I recommend that you do so. Generally, this means that every time you sign in, as part of that process, after entering your password, 23andMe will text a code to your phone or email one to you, or you can utilize a third-party authenticator application. Essentially, this adds a a third step that communicates with you through some methodology that you control, in addition to your username and password. Yes, 2FA can be a pain, but it works. You’ll find information, here.

The Relatives in Common Change Before the Compromise

I was writing about this change when all Hades broke loose with this data compromise.

A week or two prior to the compromise, 23andMe made what may have appeared to them to be “cosmetic” changes, but to genealogists, 23andMe made genealogy and triangulation much more tedious and difficult. Certainly not impossible, just requiring several steps instead of one.

Previously, Relatives in Common under DNA Overlap said “yes” or “no.” Yes meant that me, a match (Tim), and a third person (Tony) triangulated. No meant we all matched each other but no triangulation.

The 23andMe change replaced yes and no with “Compare.” That meant that customers were required to complete the following steps to get to “yes” or “no.”

  • You compared to person A (Tim)
  • You compared to person B (Tony)
  • Person A compared to person B (Tim to Tony)

It went from easy to painful, and now, since the compromise, it’s gone altogether.

Before I move on to what else has changed, I want to comment on the original change. I don’t think it’s connected to the current exposure situation, but I have no insider knowledge.

Given my background in technology, creating a permanent yes/no link means storing the relationships of each DNA segment to your matches, which quickly become a HUGE three-dimensional matrix. Storage requirements would be substantial. If you only compare three people when requested, those storage requirements disappear. Storage = $$$, and 23andMe has been struggling financially for some time.

23andMe stock is down 62% year to date, 72% since this time last year, and 92% over five years.

Based on this data, my assumption was that 23andMe was trying to save money, shaving anything anywhere it could. Genealogists were hoping to convince 23andMe to reverse their decision, but now it’s a moot point because DNA Relatives is gone altogether, at least for now, and 23andMe has much, much larger fish to fry.

23andMe Update

23andMe provided an update on their blog about changes they’ve made related to DNA Relatives, here.

However, DNA Relatives is ONLY HALF THE PROBLEM. 23andMe did not address the rest.

  1. A Direct Compromise – Your data was very clearly compromised IF YOUR ACCOUNT WAS DIRECTLY COMPROMISED. This means the situation where the bad actor was able to sign on to your account as you because your email and password were found in other data breaches. If you’ve ever reused a password, you have no way of knowing if your account was compromised and you must assume it was.
  2. Compromise Through DNA Relatives Matching – Your DNA Relatives information, as described in this 23andMe link may have been compromised, meaning revealed if ANY OF YOUR MATCHES’ ACCOUNTS WERE COMPROMISED. In other words, your information shown to a match was exposed if any of your 1500 (non-subscriber) or 4500 (subscriber only) matches had their account directly compromised – meaning signed into because they reused a password. Less of your data was compromised than in a direct exposure, but some of it very clearly would have been exposed in this scenario.

The link 23andMe provided only addresses what can be viewed through DNA Relatives. They did not mention health information if you and any specific match have authorized that level of sharing. I have not.

That’s not all, either.

If Your Account Was Directly Compromised, Your RAW DNA File Could Have Been Downloaded

If YOUR account has been signed into, the bad actor is functioning as you, and they can download your raw DNA file, which means they could upload it elsewhere. The hacker mentioned that specifically.

You do have to request a download at 23andMe. A notification is sent to your email when the download is ready, BUT, you don’t actually need that email to retrieve your download. If you simply sign out and back in again, and return to the download function, a notification awaits you that your download is now ready. Just click to download.

If your email address used at 23andMe is functioning correctly, you would have received a notification that you had requested a DNA file download. If you received a notification like this in the past few days/weeks/months, and you did NOT request a download, please inform 23andMe immediately. This could be one way that 23andMe might be able to determine whose accounts were directly compromised, and therefore whose accounts were indirectly compromised using DNA Relatives.

In my case, I was not receiving email notifications from 23andMe because my account had been blacklisted due to carrier issues, so I would never have received that email.

If your account was one that was compromised, your file may have already been downloaded. Check your inbox and spam folder to see if you have any notifications from 23andMe that escaped your notice.

It Could Still Be Happening

23andMe can only do so much.

They can force users to select a new password, but they can’t prevent people from reusing a different password, which means that the bad actor could still be trying to sign on to accounts – and getting into some.

Genealogy, including DNA is a team sport. We have to depend on our matches.

23andMe could force everyone to use 2FA, but so far they have not opted to do that, probably because it would be very unpopular.

Additional Changes

The following DNA Relatives features have either been temporarily or permanently disabled or removed:

  • Download matches (which included matching segments) is no longer available
  • Relatives in common (three-way matching) is disabled entirely, so there are no shared matches or shared segments
  • Viewing how your matches match each other is gone
  • The chromosome browser is gone

However, other tools such as the family tree which shows relationships and health sharing are still available.

At 23andMe, What Can You Do?

Truthfully, I’ve been a hair’s breadth from deleting all of my tests at 23andMe for days. I manage two tests of my own and other relatives’ too.

23andMe has never been committed to genealogy and was always the least useful site for me. Having said that, I have had some close and very useful matches there that aren’t elsewhere.

I’m certainly never testing there again, but I really don’t want to give up on 23andMe altogether, at least not yet. I’ve already paid for several tests, and I would lose valuable information today, and the potential of the same in the future.

We can’t undo any damage that has already been done. That ship has sailed. However, we can take steps to protect ourselves, both today and tomorrow. In other words, we have options other than deleting our tests.

I’ve decided to pause, at least for now.

The Pause Strategy

Only you can protect yourself by selecting a unique, strong password. Not just at 23andMe, but every site you use on the internet for any purpose.

Until and unless 23andMe requires 2FA, you need to decide on a strategy to protect yourself from other people’s negligence.

You don’t have to permanently delete your tests. Instead, you can disable DNA Relatives, which means matching.

I’ve opted-out of DNA Relatives while waiting to see what happens as 23andMe works through this quagmire. That means that I’m not participating directly in matching anymore. I’ve also opted all of the tests I manage out as well. I can always opt back in when this problem is resolved, if that ever happens.

Opting-Out of DNA Relatives

Here’s how to opt-out.

Under the Ancestry tab, select DNA Relatives.

Click on Edit profile.

Scroll all the way to the very bottom.

At the bottom, click on “I would like to stop participating in DNA Relatives.

I clicked on “Finish,” then verified that this profile is not shown as a match.

My profile prior to disabling DNA Relatives looked like this:

These same fields after disabling DNA Relatives.

Unfortunately, it does not appear that you can disable Connections broadly.

Apparently, you need to disable Connections one by one. I know that Connections can still see you, but they can’t see everything. You can find instructions here.

What I’d really like is an “invisibility” function that simply stops all sharing by making me invisible until I want to be visible again, without deleting my accounts. I’m more than a little irritated that connections remained, other than within the accounts I actually manage.

I still have not decided if I will eventually retain or delete my accounts, but disabling DNA Relatives helps somewhat and buys me some pause time while I make a final decision about 23andMe.

Your decision may not be as difficult. In addition to my genealogy research, I depend on my accounts at the various vendors for instructional articles for my blog.

Minimum Two Steps

No matter what else you do, implement the following NOW:

  1. Use a unique, difficult-to-guess, strong password at every vendor. Here and here are some ideas and guidelines for strong passwords.
  2. Turn on 2-factor authentication.
  3. If you did not previously use a unique password at 23andMe, presume your data was compromised.
  4. If you have to assume your data was compromised, be hyper-vigilant of anything unusual or strange.
  5. Check to see if your email address associated with 23andme received a DNA file download request that you did not initiate, and if so, notify 23andMe immediately at customercare@23andme.com or 1-800-239-5230.

Other Companies

Other DNA testing companies are taking precautions and reviewing safeguards. Some have or may disable some features as they move through the process. Don’t be angry if a feature you depend on is gone for now.

The situation is changing very rapidly. I don’t know if the changes at the vendors, including 23andMe, will be permanent, and the companies probably don’t yet either.

Right now, overall, patience is the word as this mess sorts itself out – but while being patient, be sure to review your own safeguards and follow safe online practices.

_____________________________________________________________

Follow DNAexplain on Facebook, here.

Share the Love!

You’re always welcome to forward articles or links to friends and share on social media.

If you haven’t already subscribed (it’s free,) you can receive an email whenever I publish by clicking the “follow” button on the main blog page, here.

You Can Help Keep This Blog Free

I receive a small contribution when you click on some of the links to vendors in my articles. This does NOT increase the price you pay but helps me to keep the lights on and this informational blog free for everyone. Please click on the links in the articles or to the vendors below if you are purchasing products or DNA testing.

Thank you so much.

DNA Purchases and Free Uploads

Genealogy Products and Services

My Book

Genealogy Books

Genealogy Research