Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    YouTube TV could lose Fox channels this week

    August 25, 2025

    The new entry-level Kindle Colorsoft is $30 off for a limited time

    August 25, 2025

    The Trump-Intel Deal Is Official

    August 25, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Internet Archive Breach Exposes 31 Million Users
    Security

    Internet Archive Breach Exposes 31 Million Users

    News RoomBy News RoomOctober 12, 20243 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    An illicit JavaScript pop-up on the Internet Archive proclaimed on Wednesday afternoon that the site had suffered a major data breach. Hours later, the organization confirmed the incident.

    Longtime security researcher Troy Hunt, who runs the data-breach-notification website Have I Been Pwned (HIBP) also confirmed that the breach is legitimate. He said it occurred in September and that the stolen trove contains 31 million unique email addresses along with usernames, bcrypt password hashes, and other system data. Bleeping Computer, which first reported the breach, also confirmed the validity of the data.

    “Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach?” the attackers wrote in Wednesday’s Internet Archive pop-up message. “It just happened. See 31 million of you on HIBP!”

    In addition to the breach and site defacement, the Internet Archive has been grappling with a wave of distributed denial-of-service attacks that have intermittently brought down its services.

    “The Internet Archive’ services have been taken offline to recover from ongoing intermittent DDoS attacks,” Internet Archive founder Brewster Kahle told WIRED on Thursday. He added that he will provide further updates through his X account.

    Kahle provided a public update on Wednesday evening in a post on X. “What we know: DDOS attack—fended off for now; defacement of our website via JS library; breach of usernames/email/salted-encrypted passwords. What we’ve done: Disabled the JS library, scrubbing systems, upgrading security. Will share more as we know it.” “Scrubbing systems” refer to services that offer DDoS attack protection by filtering malicious junk traffic so it can’t deluge and disrupt a website.

    The Internet Archive has faced aggressive DDoS attacks numerous times in the past, including in late May. As Kahle wrote on Wednesday: “Yesterday’s DDoS attack on @internetarchive repeated today. We are working to bring http://archive.org back online.” The hacktivist group known as BlackMeta claimed responsibility for this week’s DDoS attacks and said it plans to carry out more against the Internet Archive. Still, the perpetrator of the data breach is not yet known.

    The Internet Archive has faced battles on many fronts in recent months. In addition to repeated DDoS attacks, the organization is also facing mounting legal challenges. It recently lost an appeal in Hachette v. Internet Archive, a lawsuit brought by book publishers, which argued that its digital lending library violated copyright law. Now it’s facing an existential threat in the form of another copyright lawsuit, this one from music labels, which may result in damages upwards of $621 million if the court rules against the archive.

    HIBP’s Hunt says that he first received the stolen Internet Archive data on September 30, reviewed it on October 5, and warned the organization about it on October 6. He says the group confirmed the breach to him the next day and that he planned to load the data into HIBP and notify its subscribers about the breach on Wednesday. “They get defaced and DDoS’d, right as the data is loading into HIBP,” Hunt wrote. “The timing on the last point seems to be entirely coincidental.”

    Hunt added, too, that while he encouraged the group to publicly disclose the data breach itself before the HIBP notifications went out, the extenuating circumstances may explain the delay.

    “Obviously I would have liked to see that disclosure much earlier, but understanding how under attack they are, I think everyone should cut them some slack,” Hunt wrote. “They’re a nonprofit doing great work and providing a service that so many of us rely heavily on.”

    Update 2:30 pm ET, October 10, 2024: Added comment from Internet Archive founder Brewster Kahle.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleHurricane Milton Shows How a Storm’s Category Doesn’t Tell the Full Story
    Next Article An International Space Station Leak Is Getting Worse—and Keeping NASA Up at Night

    Related Posts

    A Special Diamond Is the Key to a Fully Open Source Quantum Sensor

    August 25, 2025

    Data Brokers Face New Pressure for Hiding Opt-Out Pages From Google

    August 23, 2025

    493 Cases of Sextortion Against Children Linked to Notorious Scam Compounds

    August 20, 2025

    Russia Is Cracking Down on End-to-End Encrypted Calls

    August 19, 2025

    The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived

    August 19, 2025

    Data Brokers Are Hiding Their Opt-Out Pages From Google Search

    August 19, 2025
    Our Picks

    The new entry-level Kindle Colorsoft is $30 off for a limited time

    August 25, 2025

    The Trump-Intel Deal Is Official

    August 25, 2025

    Google Nest Camera and Doorbell leak shows off new colors and 2K video recording

    August 25, 2025

    Elon Musk’s xAI is suing OpenAI and Apple

    August 25, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Business

    Astronomer’s New CEO Speaks—Yes, About That

    By News RoomAugust 25, 2025

    The only people from Astronomer attending the Coldplay concert in Foxborough, Massachusetts, on July 16…

    This $1,700 LED Mask Feels More Like Punishment Than Self-Care

    August 25, 2025

    Our favorite smart lock is on sale for the first time today

    August 25, 2025

    AI doesn’t belong in journaling

    August 25, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.