Or did the perpetrators just pull login details as it’s the only useful information?
Or did the perpetrators just pull login details as it’s the only useful information?
It's quite common to store just what's needed for logins in it's own table.
There's more to that sentence. Outside of enterprise corporations, I've never actually seen an application database user with permissions to the user credentials table but not the rest of the tables in the database related to that application.
Also their statement "We have no reason to believe that any other MyHeritage systems were compromised" is a fancy way of saying "we have no idea what happened" and equivalent in my mind to "We have no reason to believe that any other MyHeritage systems were not compromised.
"The good news is there are apparently three entirely separate databases. There is the user login account database. There is the financial credit card charging-people-for-the-service database. And also, separate from either of those two, is the genealogy we've-got-your-DNA-that-you-uploaded-to-us database."