Internet Archive breach exposed 31 million user records
- Organization
- Internet Archive
- Exploit
- Hacking
- Industry
- Nonprofit
The Internet Archive, the San Francisco nonprofit behind the Wayback Machine, spent much of October 2024 dealing with three overlapping security problems: the theft of user account data, a defacement of its website, and repeated denial of service attacks.
The account data surfaced first. A database containing 31,081,179 unique records was passed to the breach notification service Have I Been Pwned at the end of September and loaded on October 9. It held email addresses, screen names, usernames and bcrypt password hashes, with the most recent entries timestamped September 28, 2024. Reporting traced the intrusion to a GitLab authentication token that had been left exposed since late 2022, which the attacker used to reach source code and user data.
Around the same time, visitors to archive.org were shown a JavaScript pop-up taunting the organization about the breach, and the hacktivist group SN_BlackMeta claimed a distributed denial of service campaign that knocked the site and the Wayback Machine offline. Founder Brewster Kahle said the library had disabled the JavaScript library, was scrubbing its systems and was upgrading security. The Wayback Machine returned in read-only form in mid-October, with the Save Page Now feature still unavailable.
A further intrusion followed on October 20, when an attacker used Zendesk API tokens that had never been rotated to reach the Archive's support platform, including old tickets containing identification documents users had submitted. Registered users were advised to change their passwords.