Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.
Intelligence analysis by Llama

Thermo Fisher has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.
Imagine you have a DNA file that contains information about a person. If someone with the right access and knowledge can modify this file, they can change the information it contains. This is like changing a document's contents without anyone noticing. Thermo Fisher has fixed a flaw that could have allowed this to happen, but it's still important to be careful with sensitive information.
Analysis
A $60B Vote of Confidence
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.
The researchers told The Wall Street Journal that an attacker would need local or remote access to a laboratory's servers and enough knowledge of how DNA testing works. The updates cover five Applied Biosystems human identification product lines: 3500/3500xL Series Data Collection Software 4.0.2 and earlier, fixed in 4.0.3 3730/3730xL Series Data Collection Software 5.0.2 and earlier, fixed in 5.0.3 SeqStudio Genetic Analyzer Data Collection Software 1.2.5 and earlier, fixed in 1.2.6 SeqStudio Flex Series Instrument Software 1.2.0 and earlier, fixed in 1.2.1. Labs using SeqStudio Flex with security, audit, and electronic signature (SAE) enabled must first install the latest SAE profile on the SAE Admin Console GeneMapper ID-X Software v1.7.3 and earlier, fixed in v1.7.4
Three older lines get nothing: 3130 Series Data Collection Software 4.1 and earlier, ABI PRISM 3100/3100-Avant Data Collection Software 2.0 and earlier, and ABI PRISM 310 Data Collection Software 3.1 and earlier. Thermo Fisher says each has reached end of life and will receive no update.
Thermo Fisher's recommended measures for customers unable to implement the updates or use another third-party analysis platform include maintaining chain of custody, storing files on encrypted and password-protected media, restricting access, applying least privilege on instrument and analysis systems, and limiting internet connectivity to trusted sources.
Key points
- Thermo Fisher has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.
- The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.
- The updates cover five Applied Biosystems human identification product lines: 3500/3500xL Series Data Collection Software 4.0.2 and earlier, fixed in 4.0.3 3730/3730xL Series Data Collection Software 5.0.2 and earlier, fixed in 5.0.3 SeqStudio Genetic Analyzer Data Collection …
- Three older lines get nothing: 3130 Series Data Collection Software 4.1 and earlier, ABI PRISM 3100/3100-Avant Data Collection Software 2.0 and earlier, and ABI PRISM 310 Data Collection Software 3.1 and earlier.
If Thermo Fisher's updates are widely adopted, it could lead to improved data security and integrity in the DNA testing industry. This could also lead to increased trust in the results of DNA tests, which is crucial for various applications such as forensic science and genetic research.
If the flaw is not properly addressed, it could lead to compromised data integrity and security in the DNA testing industry. This could have serious consequences, including incorrect conclusions drawn from DNA tests and potential misuse of sensitive information.



