Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

31 Million Users Affected by Internet Archive Hack

The Internet Archive has been hacked and hit by a significant DDoS attack, with 31 million users reportedly being impacted by a data breach.

Internet Archive hacked

The Internet Archive has confirmed getting hacked and suffering a data breach, with as many as 31 million users reportedly being impacted.

The Internet Archive is a non-profit digital library hosting millions of applications, videos, audio files, print materials, and images. Its Wayback Machine service has captured hundreds of billions of web pages.

According to Troy Hunt, the administrator of the popular data breach notification service Have I Been Pwned (HIBP), data taken from the Internet Archive started circulating at some point before September 30. 

Hunt managed to analyze the data on October 5 and uploaded it to HIBP on October 9 to allow users to check if they are impacted. 

Over 31 million compromised Internet Archive records have been added to HIBP, including email addresses, usernames, and password hashes (generated with the Bcrypt algorithm). 

It’s worth noting that the difficulty of cracking Bcrypt-hashed passwords depends on the strength of the password — it can be done within minutes if the password is weak, but it can take millions or billions of years to crack strong passwords. 

Advertisement. Scroll to continue reading.

In addition to the data breach, the Internet Archive website was defaced with a message announcing the breach, and the site went offline several times in the past few days due to a DDoS attack.

The Internet Archive has yet to share any details, but its founder, Brewster Kahle, has confirmed that the service has been offline for much of the time since Tuesday due to a DDoS attack. The website is still offline at the time of writing. 

Kahle has also confirmed that the Internet Archive website has been defaced (blamed on a JavaScript library), and that usernames, email addresses, and salted and encrypted passwords have been compromised.

“What we’ve done: Disabled the JS library, scrubbing systems, upgrading security,” Kahle said in the latest update shared on X. 

Related: Casio Hit by Cyberattack

Related: CreditRiskMonitor Data Breach Impacts Employee Information

Related: Physical Security Firm ADT Hacked Again

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.