Index  ›  crime  ›  TechRadar
crime · TechRadar ↗

Researchers used AI-assisted code to undetectably tamper with data from computerized scans of physical DNA evidence produced by widely used crime-lab machines — vulnerable DNA files ‘lack the same level of tamper-evident markings that we require for a paper bag’

TechRadar Published Aug 3, 2026 Reviewed Aug 3, 2026 ✓ Reviewed by citations.press editors
Researchers used AI-assisted code to undetectably tamper with data from computerized scans of physical DNA evidence produced by widely used crime-lab machines — vulnerable DNA files ‘lack the same level of tamper-evident markings that we require for a paper bag’
The vulnerability affects DNA files made by crime labs since 1995, putting 30 years of crime files at risk of tampering.
30 years · crime files researchers, forensic and computer scientists
Thermo Fisher Scientific privately acknowledged the DNA file vulnerability in July 2026.
Thermo Fisher Scientific, company
Thermo Fisher Scientific said a fix for the DNA file vulnerability is currently in progress.
Thermo Fisher Scientific, company
Nathan Adams, a systems engineer at Forensic Bioinformatics, successfully exploited the DNA file vulnerability in just 45 minutes using Anthropic’s Claude.
45 minutes · test duration Nathan Adams, systems engineer at Forensic Bioinformatics
The lack of a centralized regulator on forensics has left over 200 labs with a patchwork of security measures.
more than 200 labs · labs Sarah Chu, director of policy and reform at Perlmutter Center for Legal Justice
Thermo Fisher Scientific released a software update that implements digital signatures to add an extra layer of protection for DNA file integrity.
Thermo Fisher Scientific, company
Researchers warned that AI tools could be used to add or remove DNA profiles from crime-scene evidence, potentially removing a suspect’s DNA or adding an innocent person’s DNA.
researchers, forensic and computer scientists
Researchers said they could not find a way to detect if tampering had taken place in the DNA files.
researchers, forensic and computer scientists

A group of forensic and computer scientists have raised concerns about the security of software used by top US crime labs to analyze DNA evidence.

By using an AI model, the researchers were able to undetectably modify computerized scans of physical DNA evidence, exclusive Wall Street Journal reported. As the vulnerability relates to digital files made by crime labs since 1995, the vulnerability places 30 years of crime files at risk of being tampered with.

“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag,” said Laura Gaydosh Combs, a University of New Haven professor and forensic scientist who contributed to the research.

The researchers disclosed the vulnerability in May. Thermo Fisher Scientific, the company that builds the crime-lab equipment used across most US facilities, privately acknowledging the vulnerability in July 2026. The company said that a fix is currently in progress.

In a separate note to customers, Thermo Fisher Scientific said there were no known instances of the vulnerability being exploited.

But the researchers themselves have said that they could not find a way to detect if tampering had taken place. The vulnerability was tested by Nathan Adams, a systems engineer at Forensic Bioinformatics. In just 45 minutes, Adams managed to successfully exploit the vulnerability using Anthropic’s Claude, and modify a file.

Despite some of the files being sealed using a more advanced encryption algorithm, Adams was able to find and use a decryption key available on the internet to crack into these files.

The researchers highlighted that by using AI tools to gain the necessary skills and tools, a hacker could abuse the vulnerability to add or remove DNA profiles from crime-scene evidence. Therefore allowing a suspect’s DNA to be removed, or an innocent person’s DNA added.

“Lessons learned from other industries haven’t been imported into forensic science in a serious way,” said Sarah Chu, the director of policy and reform at the Perlmutter Center for Legal Justice who worked on the research. “We’ve been behind the ball for so long. That kind of all rolls downhill into this incident.”

The lack of any centralized regulator on forensics has left over 200 labs with a patchwork of security measures, Chu added.

In a statement to the WSJ, Thermo Fisher Scientific said, “We have been working closely with the U.S. Cybersecurity and Infrastructure Agency since the software issue was raised. We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified.”

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.

Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.

Please logout and then login again, you will then be prompted to enter your display name.

This article was originally published by TechRadar ↗. citations.press indexes the source-backed facts above and links to the original. Something wrong? Corrections policy · Report an error