'We’ve been behind the ball for so long': Experts say DNA samples from crime-scene forensics can be modified and even switched using an AI tool
Researchers discover critical vulnerability in forensic software that allows the undetectable modification of DNA samples on crime-scene evidence The vulnerability allows much of the crime-scene evidence from the past 30 years to be modified A patch is in the works, and the company responsible for t
<![CDATA[ <article> <ul><li><strong>Researchers discover critical vulnerability in forensic software that allows the undetectable modification of DNA samples on crime-scene evidence</strong></li><li><strong>The vulnerability allows much of the crime-scene evidence from the past 30 years to be modified</strong></li><li><strong>A patch is in the works, and the company responsible for the software says that digital signatures have been implemented to monitor for modification attempts</strong></li></ul><p>A group of forensic and computer scientists have raised concerns about the security of software used by top US crime labs to analyze DNA evidence.</p><p>By using an AI model, the researchers were able to undetectably modify computerized scans of physical DNA evidence, exclusive <a href="https://www.wsj.com/tech/cybersecurity/security-flaw-placed-30-years-of-dna-evidence-at-risk-of-hacking-1932775a?st=zGgyGg&reflink=desktopwebshare_permalink" target="_blank" rel="nofollow"><em>Wall Street Journal</em></a> reported. As the vulnerability relates to digital files made by crime labs since 1995, the vulnerability places 30 years of crime files at risk of being tampered with.</p><p>“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag,” said Laura Gaydosh Combs, a University of New Haven professor and forensic scientist who contributed to the research.</p><h2 id="no-known-instances-of-undetectable-exploitation">No known instances of ‘undetectable’ exploitation</h2><p>The researchers disclosed the vulnerability in May. Thermo Fisher Scientific, the company that builds the crime-lab equipment used across most US facilities, privately acknowledging the vulnerability in July 2026. The company said that a fix is currently in progress.</p><p>In a separate note to customers, Thermo Fisher Scientific said there were no known instances of the vulnerability being exploited.</p><p>But the researchers themselves have said that they could not find a way to detect if tampering had taken place. The vulnerability was tested by Nathan Adams, a systems engineer at Forensic Bioinformatics. In just 45 minutes, Adams managed to successfully exploit the vulnerability using Anthropic’s Claude, and modify a file.</p><p>Despite some of the files being sealed using a more advanced encryption algorithm, Adams was able to find and use a decryption key available on the internet to crack into these files.</p><p>The researchers highlighted that by using AI tools to gain the necessary skills and tools, a hacker could abuse the vulnerability to add or remove DNA profiles from crime-scene evidence. Therefore allowing a suspect’s DNA to be removed, or an innocent person’s DNA added.</p><p>“Lessons learned from other industries haven’t been imported into forensic science in a serious way,” said Sarah Chu, the director of policy and reform at the Perlmutter Center for Legal Justice who worked on the research. “We’ve been behind the ball for so long. That kind of all rolls downhill into this incident.”</p><p>The lack of any centralized regulator on forensics has left over 200 labs with a patchwork of security measures, Chu added.</p><p>In a statement to the <em>WSJ</em>, Thermo Fisher Scientific said, “We have been working closely with the U.S. Cybersecurity and Infrastructure Agency since the software issue was raised. We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified.”</p> </article> ]]>
Read the full article on TechRadar
Read Full Article →