US crime lab DNA files vulnerable to undetectable tampering, researchers say
A security vulnerability in software used by most U.S. forensic laboratories left digital DNA analysis files vulnerable to undetectable tampering for nearly three decades, according to researchers, prompting equipment maker Thermo Fisher Scientific to issue a high-severity security alert and release a software update.
The flaw affected digital DNA files generated since about 1995. Researchers found that AI-assisted computer code could modify DNA analysis files without leaving evidence that the records had been altered, The Wall Street Journal (WSJ) writes.
They said the vulnerability does not affect physical DNA samples and that there is no evidence it has been exploited.
Thermo Fisher Scientific, whose equipment is used in most U.S. crime laboratories, acknowledged the issue after researchers reported it and on Friday warned of "a risk for nearly undetectable modification" of certain files "if laboratory controls are circumvented."
The company said it had released a software update introducing digital signatures to help laboratories verify that DNA files have not been modified.
"We have been working closely with the U.S. Cybersecurity and Infrastructure Security Agency since the software issue was raised," the company said. "We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified."
"Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag," said Laura Gaydosh Combs, a forensic scientist and professor at the University of New Haven.
The researchers said exploiting the flaw would require access to a laboratory's servers and knowledge of forensic DNA analysis, but advances in AI have made such tampering easier. It remains unclear whether the vulnerability could affect past or pending criminal cases.
By Aghakazim Guliyev







