DNA Diagnostics Center (DDC), an Ohio-based DNA testing company, disclosed a hacking incident that affected 2,102,436 people.

See also: Ukraine arrests hackers from the "Phoenix" group
The incident led to a confirmed data breach that occurred between May 24, 2021, and July 28, 2021, but the company discovered it on October 29, 2021.
The information that the hackers accessed includes the following:
- Full names
- Credit card number + CVV
- Debit card number + CVV
- Financial account number
- Platform account password
The compromised database contained older backups dating between 2004 and 2012 and is not connected to the active systems and databases currently used by DNA Diagnostics Center (DDC).
DDC is working with external cybersecurity experts to regain possession of the stolen files and ensure that the threat actor does not distribute them further. So far, there have been no reports of fraud or malicious use of the stolen data.
Affected individuals will receive a notification letter and instructions for their free annual subscription to credit monitoring and identity theft protection services through Experian.
See also: Hackers exploited flaw in popular e-commerce software

Recipients of these alerts are advised to remain vigilant for fraud and to frequently monitor their bank account statements to identify any suspicious activity. Of course, they should report it immediately.
The DNA Diagnostics Center (DDC) emphasizes that no genetic testing data has been exposed due to the data breach incident, as it is stored on a different system.
See also: Hackers deploy Linux malware on e-commerce servers
Apparently the company keeps a lot of sensitive data since it conducts paternity tests, DNA tests for family relationships, fertility, COVID-19, ancestry, and tests for immigration purposes.
However, according to the announcement, nothing related to these services has been breached.
Information source: bleepingcomputer.com
