
Thermo Fisher Scientific has patched a vulnerability in its Applied Biosystems human identification software that could allow an attacker with access to a forensics laboratory’s systems to alter DNA output files in ways that analysis software would not detect. The flaw affects .fsa and .hid output files produced by the company’s DNA sequencing instruments — the same file types used to generate DNA profiles in criminal investigations, paternity cases, and disaster victim identification. Researchers who discovered the issue demonstrated that a modified file could appear to have been produced in 2015 with no visible warning from commonly used analysis software. According to the researchers, the vulnerability has likely existed in digital DNA files since 1995, when the affected format was first introduced.
The security bulletin, published by Thermo Fisher on July 31, 2026, does not specify what level of system access an attacker would need, but the researchers told the Wall Street Journal that local or remote access to a laboratory’s servers — along with knowledge of how DNA testing works — would be required. No confirmed case of casework tampering has been publicly linked to this vulnerability. Thermo Fisher credits Nathan Adams of Forensic Bioinformatics, Kevin Dyer, and Laura Gaydosh Combs for identifying and disclosing the issue, with coordination from CISA. Five current Applied Biosystems product lines receive updates; three older product lines — the 3130 Series Data Collection Software 4.1 and earlier, ABI PRISM 3100/3100-Avant 2.0 and earlier, and ABI PRISM 310 3.1 and earlier — have reached end of life and will receive no patch. Thermo Fisher recommends that labs unable to update maintain strict chain of custody, store files on encrypted password-protected media, restrict access to instrument and analysis systems, and limit internet connectivity to trusted sources.
How to check if you’re affected
Affected products include any of the five current Applied Biosystems human identification product lines listed in the July 31 bulletin. If your lab runs one of the three end-of-life products (3130 Series 4.1 and earlier, ABI PRISM 3100/3100-Avant 2.0 and earlier, or ABI PRISM 310 3.1 and earlier), no patch is available — apply the compensating controls described above and consult your laboratory’s legal and compliance teams about chain-of-custody documentation for existing case files. For current product lines, install the applicable updates immediately using the guidance in the security bulletin.
