Earlier this month, genealogy website FamilySearch announced A hacker broke into the system and stole personal data about the user.
The site, run by the Church of Latter-day Saints (better known as Mormons) and billing itself as “the world’s largest shared genealogy,” emailed affected users on October 13, 2022 about the data breach. I notified you.
The email begins like this:
Dear Account Holder:
FamilySearch International (“FSI”), a Utah non-profit organization, has detected an unauthorized network intrusion affecting previously provided personal data. At this time, there are no indications that the data has been or could be used for fraudulent or other harmful purposes. Affected data did not include user genealogy data. We notify users worldwide that their data may have been affected, even if we are not legally required to do so.
Yes, they are notifying people whose data may have been affected, “even if this is not legally required”.
That’s their good point.
But wait, read some more…
“On March 23, 2022, we detected unauthorized access to certain computer systems. We immediately notified U.S. federal law enforcement agencies. I have been asked to keep it. This order will be lifted on October 12, 2022.”
Hmmm.. hackers stole data like user full name, gender, email address, date of birth, mailing address, phone number etc. (all useful information that could be misused by scammers) …but FamilySearch does it.
But don’t worry…
Affected data did not include user genealogy data.
So your great-great-great-great-grandmother has nothing to worry about.
FamilySearch says it can’t pin down who hacked the system, but U.S. law enforcement officials say the intrusion “has taken effect on organizations and governments around the world that weren’t intended to harm any individual.” We suspect it was part of a pattern of targeted, state-sponsored cyberattacks.
So don’t worry…
Because you will spend a lot of time changing your name, gender, date of birth, etc.
But seriously, shouldn’t affected users have been notified sooner? Is it possible to delay the notification by more than half a year?
It turns out that FamilySearch users weren’t the only ones whose data was stolen. The same hackers also apparently attacked the genealogy site’s owner, the Mormon Church. Steal personal information of church members, employees, contractors and friends.
Did you find this article interesting? Follow Graham Cluley on Twitter To read more about the exclusive content we post.