Data leak

Internet Archive (Wayback Machine) data breach

πŸ“… 2024-09-28 🏒 Internet Archive / archive.org
Primary Source β†—

Incident Details

Threat actor (SN_BlackMeta, linked to pro-Palestinian hacktivist movement) defaced archive.org with a JavaScript alert and simultaneously exfiltrated a 6.4 GB SQL file ‘ia_users.sql’ containing 31 million user records (email addresses, screen names, bcrypt password hashes, timestamps). Breach data current to 28 September 2024; disclosed 9 October when defacement appeared on site. Data shared with Have I Been Pwned; 54% of records already in HIBP. Internet Archive confirmed archival material was safe. A simultaneous DDoS attack also disrupted service.

Technical Details

Initial Attack Vector
CWE-312: Cleartext Storage of Sensitive Information (authentication database exfiltrated; separately DDoS and defacement via JavaScript injection)
Vendor / Product
Internet Archive / archive.org

Timeline

  1. 2024-09-28 Breach occurred
  2. 2024-10-09 Publicly disclosed
  3. 2024-10-09 Customers notified