Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    FCC approves Verizon’s $20 billion merger after it commits to ‘ending’ DEI

    May 16, 2025

    Microsoft’s Command Palette is a powerful launcher for apps, search, and more

    May 16, 2025

    REI’s anniversary sale is dropping prices on Garmins and other great outdoor gear

    May 16, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Internet Archive Breach Exposes 31 Million Users
    Security

    Internet Archive Breach Exposes 31 Million Users

    News RoomBy News RoomOctober 12, 20243 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    An illicit JavaScript pop-up on the Internet Archive proclaimed on Wednesday afternoon that the site had suffered a major data breach. Hours later, the organization confirmed the incident.

    Longtime security researcher Troy Hunt, who runs the data-breach-notification website Have I Been Pwned (HIBP) also confirmed that the breach is legitimate. He said it occurred in September and that the stolen trove contains 31 million unique email addresses along with usernames, bcrypt password hashes, and other system data. Bleeping Computer, which first reported the breach, also confirmed the validity of the data.

    “Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach?” the attackers wrote in Wednesday’s Internet Archive pop-up message. “It just happened. See 31 million of you on HIBP!”

    In addition to the breach and site defacement, the Internet Archive has been grappling with a wave of distributed denial-of-service attacks that have intermittently brought down its services.

    “The Internet Archive’ services have been taken offline to recover from ongoing intermittent DDoS attacks,” Internet Archive founder Brewster Kahle told WIRED on Thursday. He added that he will provide further updates through his X account.

    Kahle provided a public update on Wednesday evening in a post on X. “What we know: DDOS attack—fended off for now; defacement of our website via JS library; breach of usernames/email/salted-encrypted passwords. What we’ve done: Disabled the JS library, scrubbing systems, upgrading security. Will share more as we know it.” “Scrubbing systems” refer to services that offer DDoS attack protection by filtering malicious junk traffic so it can’t deluge and disrupt a website.

    The Internet Archive has faced aggressive DDoS attacks numerous times in the past, including in late May. As Kahle wrote on Wednesday: “Yesterday’s DDoS attack on @internetarchive repeated today. We are working to bring http://archive.org back online.” The hacktivist group known as BlackMeta claimed responsibility for this week’s DDoS attacks and said it plans to carry out more against the Internet Archive. Still, the perpetrator of the data breach is not yet known.

    The Internet Archive has faced battles on many fronts in recent months. In addition to repeated DDoS attacks, the organization is also facing mounting legal challenges. It recently lost an appeal in Hachette v. Internet Archive, a lawsuit brought by book publishers, which argued that its digital lending library violated copyright law. Now it’s facing an existential threat in the form of another copyright lawsuit, this one from music labels, which may result in damages upwards of $621 million if the court rules against the archive.

    HIBP’s Hunt says that he first received the stolen Internet Archive data on September 30, reviewed it on October 5, and warned the organization about it on October 6. He says the group confirmed the breach to him the next day and that he planned to load the data into HIBP and notify its subscribers about the breach on Wednesday. “They get defaced and DDoS’d, right as the data is loading into HIBP,” Hunt wrote. “The timing on the last point seems to be entirely coincidental.”

    Hunt added, too, that while he encouraged the group to publicly disclose the data breach itself before the HIBP notifications went out, the extenuating circumstances may explain the delay.

    “Obviously I would have liked to see that disclosure much earlier, but understanding how under attack they are, I think everyone should cut them some slack,” Hunt wrote. “They’re a nonprofit doing great work and providing a service that so many of us rely heavily on.”

    Update 2:30 pm ET, October 10, 2024: Added comment from Internet Archive founder Brewster Kahle.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleHurricane Milton Shows How a Storm’s Category Doesn’t Tell the Full Story
    Next Article An International Space Station Leak Is Getting Worse—and Keeping NASA Up at Night

    Related Posts

    Google’s Advanced Protection for Vulnerable Users Comes to Android

    May 14, 2025

    Google Is Using On-Device AI to Spot Scam Texts and Investment Fraud

    May 14, 2025

    An $8.4 Billion Chinese Hub for Crypto Crime Is Incorporated in Colorado

    May 14, 2025

    ICE’s Deportation Airline Hack Reveals Man ‘Disappeared’ to El Salvador

    May 13, 2025

    US Border Agents Are Asking for Help Taking Photos of Everyone Entering the Country by Car

    May 13, 2025

    The Trump Administration Sure Is Having Trouble Keeping Its Comms Private

    May 12, 2025
    Our Picks

    Microsoft’s Command Palette is a powerful launcher for apps, search, and more

    May 16, 2025

    REI’s anniversary sale is dropping prices on Garmins and other great outdoor gear

    May 16, 2025

    LinkedIn Games Are Still the Best Part of LinkedIn

    May 16, 2025

    Epic’s Mega sale has big discounts on games like GTA V, Red Dead Redemption, and Cyberpunk 2077

    May 16, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    News

    Xbox is going to let you pin your favorite games on your homescreen

    By News RoomMay 16, 2025

    Microsoft is going to allow Xbox owners to pin apps and games directly to the…

    The Middle East Has Entered the AI Group Chat

    May 16, 2025

    The 24 Best Outdoor Deals From the REI Anniversary Sale

    May 16, 2025

    The State Department reportedly pressured African countries to adopt Elon Musk’s Starlink

    May 16, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.