Your cart is currently empty!
AI Helped Expose a Security Flaw That Could Have Put Three Decades of DNA Evidence at Risk

DNA evidence has long been treated as one of the strongest forms of proof in criminal investigations. Jurors trust it. Investigators rely on it. Courts often view it as the scientific standard that can confirm guilt or prove innocence.
That confidence has been shaken by a newly disclosed cybersecurity flaw that researchers say may have existed for more than 30 years. Even more surprising, they found the weakness with help from widely available artificial intelligence tools that allowed them to alter digital DNA files without leaving obvious signs of tampering.
A Hidden Weakness That May Have Existed Since 1995
The vulnerability centers on software made by Applied Biosystems, a brand owned by Thermo Fisher Scientific. The software is widely used by crime laboratories across the United States to process DNA evidence collected during criminal investigations.
According to forensic researchers, digital files generated by these systems could be modified in ways that would not trigger warnings inside the software used to analyze them. The concern does not involve changing physical DNA samples. Instead, it focuses on the electronic files created after laboratory instruments scan those samples.
The issue first came to light in May when forensic scientist Laura Gaydosh Combs, who also teaches at the University of New Haven, and Sarah Chu, director of policy and reform at the Perlmutter Center for Legal Justice, identified the security flaw during a research project.
Their findings suggested that the weakness may have been present since 1995, raising concerns about digital DNA records created over the last three decades.
According to reporting by The Wall Street Journal, the researchers demonstrated that AI-generated computer code could modify these files without leaving evidence that they had been changed. The altered records still appeared authentic to the forensic software responsible for reading them.
AI Made the Demonstration Much Easier

One reason the discovery has attracted so much attention is the role artificial intelligence played during the testing process.
Researchers said they relied on widely available AI coding tools rather than advanced hacking techniques that would require years of specialized training.
Nathan Adams, a systems engineer at Ohio-based Forensic Bioinformatics, independently tested the vulnerability using publicly available DNA datasets.
Using Anthropic’s Claude AI assistant, Adams generated computer code capable of modifying DNA analysis files. According to reports, his first successful attempt required only about 45 minutes.
That timeline surprised many cybersecurity experts because similar work previously demanded much greater technical expertise.
Adams reportedly discovered that while some forensic file types include encryption, the decryption key had already been publicly available on the internet for years. Once that hurdle was cleared, the AI-generated code handled much of the remaining work.
In one demonstration, Adams merged scans from two separate DNA profiles into a newly created file. The modified version appeared untouched since 2015 and passed through the forensic analysis software without generating any alerts.
Researchers say the experiment highlighted how quickly modern AI tools can lower technical barriers for attackers.
What Was Actually Changed?

The findings have prompted understandable concern, but researchers have stressed an important distinction.
The biological DNA samples themselves were never altered.
Instead, the vulnerability involved digital records created after laboratory machines converted physical DNA evidence into electronic data files.
That difference matters because investigators would still need access to laboratory computer systems before making any unauthorized modifications.
Researchers also emphasized that exploiting the weakness would require knowledge of forensic DNA analysis in addition to access to crime lab infrastructure.
The concern is not that anyone could alter evidence remotely with a few clicks. Rather, it is that someone with sufficient access and expertise could potentially manipulate digital records in a way existing software would fail to detect.
Laura Gaydosh Combs summarized the issue during an interview with The Wall Street Journal.
“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag.”
That comparison captures why the discovery has generated significant discussion among forensic scientists. Physical evidence collected at crime scenes follows strict chain-of-custody procedures designed to reveal any unauthorized handling. Until now, the same level of protection was not consistently built into the digital files created during DNA analysis.
Why Researchers Believe AI Changed the Equation

Cybersecurity weaknesses are nothing new.
What has changed is how quickly modern AI systems can assist people in discovering and exploiting them.
According to the researchers, the vulnerability may have existed for decades without attracting serious attention because modifying these specialized forensic files previously required significant programming knowledge.
Today’s AI coding assistants can dramatically shorten that process.
Instead of writing every line of code manually, users can describe what they want the software to accomplish and receive working code within minutes.
Researchers say that shift does not automatically create new vulnerabilities. Rather, it makes existing weaknesses far easier to exploit than they would have been only a few years ago.
The demonstration showed how an individual using commercially available AI software could produce functional code capable of modifying sensitive forensic data with relatively little effort.
That finding raises broader questions extending well beyond forensic science.
As AI tools become increasingly capable, organizations responsible for protecting sensitive information may need to rethink cybersecurity practices that were designed long before generative AI became widely available.
Thermo Fisher Says There Is No Evidence of Past Misuse

Despite the alarming nature of the findings, researchers and the manufacturer have both emphasized an important point.
There is currently no evidence that anyone has successfully exploited this vulnerability in an actual criminal case.
After researchers disclosed the issue in May, Thermo Fisher Scientific investigated the findings and later acknowledged the vulnerability.
The company subsequently released a security bulletin describing what it called “a risk for nearly undetectable modification” affecting certain DNA analysis files if laboratory controls were bypassed.
Thermo Fisher also announced software updates designed to eliminate the problem by introducing digital signatures.
Those signatures allow laboratories to verify whether files have been modified after they were originally created.
In a statement quoted by multiple reports, the company said:
“We have been working closely with the US Cybersecurity and Infrastructure Agency since the software issue was raised. We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified.”
The company also stated that it is not aware of any known instances where the vulnerability was exploited before these updates became available.
However, researchers note that determining whether historical files were ever altered may prove difficult because the original software lacked reliable methods for detecting tampering.
The Fix Is Already Rolling Out
Following the researchers’ disclosure, Thermo Fisher Scientific released software updates designed to close the security gap. The company said the updates introduce digital signatures that allow laboratories to verify whether DNA files have been altered after they are created.
Digital signatures function like a seal of authenticity. If someone changes a file after it leaves the instrument, the signature should no longer match, alerting laboratory staff that something is wrong.
The company also outlined which products are affected. Updates are available for several versions of its Applied Biosystems data collection and GeneMapper software, including systems commonly used by forensic laboratories.
Some older software versions, however, have already reached the end of their life cycle and will not receive updates. For laboratories still relying on those systems, Thermo Fisher recommends strengthening cybersecurity practices instead.
Those recommendations include maintaining a secure chain of custody for digital files, storing records on encrypted media, restricting access to authorized personnel, limiting user permissions, and using firewalls to protect laboratory networks.
These measures cannot replace software security, but they reduce the opportunities for unauthorized access.
Why the Discovery Matters Beyond One Company
The findings have sparked a wider conversation about cybersecurity across the forensic science community.
More than 200 forensic laboratories across the United States process DNA evidence for criminal investigations, paternity testing, missing persons cases, and other legal proceedings. Many rely on digital systems that were designed years before artificial intelligence became part of everyday computing.
Researchers argue that forensic technology has not always kept pace with cybersecurity standards adopted in other industries.
Sarah Chu, director of policy and reform at the Perlmutter Center for Legal Justice, believes the newly identified flaw reflects a much larger issue.
“Lessons learned from other industries haven’t been imported into forensic science in a serious way. We’ve been behind the ball for so long. That kind of all rolls downhill into this incident.”
Her comments suggest the challenge extends beyond one software package.
Banks, hospitals, and cloud service providers have spent years building systems that detect unauthorized file changes, monitor suspicious activity, and verify digital integrity. Some forensic software, by comparison, was originally developed during an era when cybersecurity threats looked very different from those seen today.
As laboratories increasingly depend on digital evidence, researchers say protecting that evidence must become as important as protecting the physical samples collected at crime scenes.

Could Past Criminal Cases Be Affected?
One of the biggest questions raised by the discovery is whether previous criminal cases could be called into question.
For now, the answer remains uncertain.
Researchers have repeatedly emphasized that they have found no evidence showing the vulnerability was ever exploited in a real investigation. Thermo Fisher has echoed that conclusion, saying there are no known instances of the flaw being used to alter evidence.
At the same time, researchers acknowledge a difficult reality.
If someone had successfully modified a DNA file years ago, existing forensic software may not have been capable of detecting the change.
That does not mean historical evidence was compromised. It simply means there is currently no reliable way to examine decades-old files and determine with certainty whether they were altered.
The distinction is important.
The vulnerability represents a potential risk rather than documented proof of widespread tampering.
Experts also point out that exploiting the weakness would not have been easy. An attacker would have needed access to a laboratory’s computer systems, technical knowledge of forensic DNA analysis, and an understanding of the software used by investigators.
Those requirements significantly narrow the pool of individuals capable of carrying out such an attack.
Still, because DNA evidence can influence decisions involving life imprisonment or even death penalty cases in some jurisdictions, researchers believe even a theoretical weakness deserves careful attention.
AI Is Changing the Cybersecurity Landscape
Although the flaw itself may date back to 1995, the story reflects a much newer reality.
Artificial intelligence is transforming cybersecurity on both sides of the equation.
Organizations increasingly use AI to identify vulnerabilities, detect suspicious activity, and strengthen digital defenses. At the same time, attackers can use the same technology to write code, automate repetitive tasks, and reduce the expertise once needed to exploit security weaknesses.
The forensic research demonstrates how quickly that balance is shifting.
Instead of spending days writing specialized software, researchers were able to use commercially available AI tools to generate functional code in less than an hour.
That speed highlights why organizations responsible for sensitive information are under growing pressure to modernize legacy systems.
Many critical industries still depend on software developed decades ago, including healthcare, transportation, manufacturing, utilities, and government agencies. As AI lowers technical barriers, systems that once appeared reasonably secure may require a fresh evaluation.
Cybersecurity experts have warned for years that older software often contains weaknesses that were never considered serious when it was first designed. AI does not necessarily create those weaknesses, but it can make them easier to discover and exploit.
Forensic science is now joining a growing list of sectors confronting that reality.
Trust in Digital Evidence Depends on Staying Ahead
DNA evidence remains one of the most powerful tools available to investigators. It has helped identify violent offenders, solve decades-old cold cases, and clear innocent people who were wrongly convicted.
None of that changes because researchers uncovered a software vulnerability.
What this discovery does show is that scientific evidence depends on more than laboratory accuracy. It also depends on the security of the digital systems that store, process, and preserve that information.
The response from researchers, software developers, and federal cybersecurity partners suggests the issue is already being addressed before any confirmed misuse has come to light.
That may ultimately become the most significant part of the story.
The same artificial intelligence that helped expose a decades-old weakness has also accelerated efforts to strengthen the systems that courts, investigators, and the public rely on every day.
