Data leak
Internet Archive (Wayback Machine) data breach
Primary Source βIncident Details
Threat actor (SN_BlackMeta, linked to pro-Palestinian hacktivist movement) defaced archive.org with a JavaScript alert and simultaneously exfiltrated a 6.4 GB SQL file ‘ia_users.sql’ containing 31 million user records (email addresses, screen names, bcrypt password hashes, timestamps). Breach data current to 28 September 2024; disclosed 9 October when defacement appeared on site. Data shared with Have I Been Pwned; 54% of records already in HIBP. Internet Archive confirmed archival material was safe. A simultaneous DDoS attack also disrupted service.
Technical Details
- Initial Attack Vector
- CWE-312: Cleartext Storage of Sensitive Information (authentication database exfiltrated; separately DDoS and defacement via JavaScript injection)
- Vendor / Product
- Internet Archive / archive.org
Timeline
- 2024-09-28 Breach occurred
- 2024-10-09 Publicly disclosed
- 2024-10-09 Customers notified