Ancestry.com Operations, Inc. disclosed that a security researcher reported a file containing 300,000 RootsWeb username/email and password combinations. The incident was discovered on December 20, 2017. Approximately 55,000 users had overlapping credentials with Ancestry commercial sites. Ancestry locked affected accounts, took RootsWeb offline, and initiated a forensic investigation. No sensitive financial or government ID data was exposed.
Affected (this filing): 300,000