Internet Archive Breached: 31 Million Users, DDoS Attack and Pop-Up Alerts

The Internet Archive, known for its “Wayback Machine,” has experienced a significant data breach, with a threat actor gaining access to the user authentication database containing 31 million unique records. This breach has raised concerns about the platform’s security infrastructure.

Internet History Hacked, Wayback Machine Down—31 Million Passwords Stolen

Reports began circulating on Wednesday afternoon when visitors to archive.org were greeted with a JavaScript alert placed by the hacker, confirming the breach. The alert read, “Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!”

The “HIBP” mentioned refers to “Have I Been Pwned,” a data breach notification service operated by cybersecurity expert Troy Hunt. Threat actors frequently share compromised data with HIBP to notify affected users. Hunt later confirmed the breach after receiving the Internet Archive’s authentication database nine days prior. The database, a 6.4GB SQL file named “ia_users.sql,” contains sensitive user information, including email addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data.

The stolen data was confirmed to be authentic, with records showing the most recent timestamp as September 28th, 2024, indicating the likely date of the breach. Hunt also contacted a number of individuals listed in the database, including cybersecurity researcher Scott Helme, who confirmed his details were compromised. Helme gave permission to apifixer.com to share this information, further verifying the breach’s legitimacy.

Of the 31 million records, many were already registered with HIBP. Once the data is added to the HIBP system, users will be able to check whether their email addresses were compromised in this breach.

Despite contacting the Internet Archive three days ago to initiate a formal disclosure process, Hunt has yet to receive a response. Meanwhile, the platform was hit by a DDoS attack earlier in the day, which has been claimed by the hacktivist group BlackMeta. The group has stated they plan to conduct further attacks on the site.

As of now, the Internet Archive has not released an official statement regarding the breach or the DDoS attack. Apifixer.com reached out to them for comment, but no immediate response was available. This news has been confirmed through multiple sources and users affected by the breach.

Further updates will follow as more information becomes available about the full scope of the breach and any potential additional security measures taken by the Internet Archive.

 

Leave a Reply

Your email address will not be published. Required fields are marked *