FB pixel

Biometric data and personal information exposure patched by genetic test lab

Biometric data and personal information exposure patched by genetic test lab
 

A genetic testing and “DNA Face Matching” company in the United States has left a trove of facial images and personally identifiable metadata exposed in a WordPress folder without even password protection, vpnMentor says.

Indiana-based ChoiceDNA left a folder titled “Facial Recognition Uploads” and containing an estimated 8,000 documents vulnerable, according to a post from Cybersecurity Researcher Jeremiah Fowler. Facial images and descriptions are considered biometric data, even if not processed for identification purposes, the FTC declared in a policy statement last year.

ChoiceDNA says its DNA Face Matching service uses biometrics to assess the likelihood that people are related. Even the identity of an individual who sought the service, therefore, could be sensitive information. The metadata accompanying the images included names, phone numbers, email addresses, ethnicity and notes on why the person was seeking DNA analysis.

Fowler disclosed the vulnerability to the company, and it was addressed within a week. No reply or indication of how long the folder had been exposed was provided.

Given the proximity of the company’s base of operations to Illinois, home of the Genetic Information Privacy Act (GIPA), there could yet be legal fallout.

Fowler also notes that “facial recognition services based on a photo that is uploaded without the photo subject’s consent raises potential ethical and privacy concerns.”

The post states that there is no indication at this point that any data was breached, and Fowler concludes with advice for protecting WordPress sites.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

UK startup raises $15M to build Europe’s sovereign alternative to biometric surveillance

A British start-up has raised millions for its biometric-alternative surveillance technology. Augur, a resilience technology startup, has raised $15 million…

 

NIST concept paper explores identity and authorization controls for AI agents

A draft concept paper released by the National Institute of Standards and Technology (NIST) asks industry and government stakeholders how…

 

Age assurance community sets new goals with standard published and use exploding

“Age Assurance Has Come of Age,” crows the Draft Summit Communiqué for the upcoming Global Age Assurance Standards Summit 2026….

 

‘Big Tech’ fears and confusion dominate dialogue over UK digital ID scheme

The UK government’s digital ID consultation has begun, its detailed plan for the process finally revealed, but all that is…

 

Bunnings introducing facial recognition to 42 New Zealand stores

Hardware and garden center chain Bunnings is introducing facial recognition technology (FRT) to its New Zealand stores to prevent serious…

 

Sweden to launch government eID in December 2026

Sweden has announced that its electronic identity (e-ID) will be launched on December 1st, 2026, giving both Swedish citizens and…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events