{"id":27578,"date":"2024-10-10T12:10:58","date_gmt":"2024-10-10T12:10:58","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=27578"},"modified":"2024-10-10T15:10:46","modified_gmt":"2024-10-10T15:10:46","slug":"archive-org-hacked","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/archive-org-hacked\/","title":{"rendered":"Archive.org Hacked, Exposing Over 31 Million Users"},"content":{"rendered":"<p><strong>Archive.org, a worldwide known archive of the entire Internet, suffered a huge data breach<\/strong>. The website was defaced, with a message from hackers saying that the site was badly secured and user data will soon be available at Have I Been Pwned service. The service already confirmed receiving the leak, with as much as 6.4GB of database uploaded to HIBP.<\/p>\n<h2>Internet Archive\u2019s Wayback Machine Hacked, User Data Stolen<\/h2>\n<p><strong>On October 9, 2024 the website of Wayback Machine service<\/strong> archive.org, led by Internet Archive organization went offline, to then get resurrected in a defaced format. <a href=\"https:\/\/gridinsoft.com\/hacker\">Hackers<\/a> who managed to break into the website\u2019s infrastructure wiped the usual contents only to place a JavaScript pop-up stating the following:<\/p>\n<div class=\"su-quote su-quote-style-default su-quote-has-cite\"><div class=\"su-quote-inner su-u-clearfix su-u-trim\">Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!<span class=\"su-quote-cite\">JS popup on the hacked site<\/span><\/div><\/div>\n<p>Unfortunately, the attacker was not kind enough to leave any other information regarding how and why they hacked the service. The website is down at the moment, even without the aforementioned JS pop-up, which suggests that Internet Archive potentially regained control over the system. At the same time, Have I Been Pwned service <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">already reports<\/a> about receiving a huge database that allegedly consists of the Internet Archive data.<\/p>\n<p>After a short browsing through this fresh upload, <strong>independent security researchers have confirmed that it is genuine<\/strong> and really is a database from Archive.org. Scott Helme, one of the investigators, shared his exposed record to BleepingComputer. Password hash (this lengthy mess of letters and numbers) corresponds to one he used on the website, and other data also appears correct.<\/p>\n<p><code style=\"font-size: 14px\">9887370, internetarchive@scotthelme.co.uk,$2a$10$Bho2e2ptPnFRJyJKIn5BiehIDiEwhjfMZFVRM9fRCarKXkemA3PxuScottHelme,2020-06-25,2020-06-25,internetarchive@scotthelme.co.uk,2020-06-25 13:22:52.7608520,\\N0\\N\\N@scotthelme\\N\\N\\N<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/archive-org-popup.png\" alt=\"Archive.org pop-up message\" width=\"756\" height=\"412\" class=\"aligncenter size-full wp-image-27586\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/archive-org-popup.png 756w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/archive-org-popup-300x163.png 300w\" sizes=\"auto, (max-width: 756px) 100vw, 756px\" \/><\/p>\n<p>Overall, the breach does not contain <a href=\"https:\/\/gridinsoft.com\/blogs\/personal-data-sensitive-data\/\">any sensitive information<\/a>, primarily because the service itself does not keep or ask for any. Main contents of the leaked database are emails, usernames and hashes of passwords. Not too much for the hackers to exploit, so the fuss is mostly about the huge number of affected users and the worldwide fame of the Archive.org service.<\/p>\n<h2>DDoS Attack of Wayback Machine<\/h2>\n<p>Aside from the massive impact from the attackers\u2019 activity, the website also suffered from SN_Blackmeta hacktivists. They have launched a DDoS attack on the Internet Archive\u2019s servers, making the site completely inaccessible for quite some time. Hackers boasted about this in their X\/Twitter publication.<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/sn-blackmeta-twitter.jpg\" alt=\"SN Blackmeta twitter\" width=\"587\" height=\"210\" class=\"aligncenter size-full wp-image-27592\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/sn-blackmeta-twitter.jpg 587w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/sn-blackmeta-twitter-300x107.jpg 300w\" sizes=\"auto, (max-width: 587px) 100vw, 587px\" \/><\/p>\n<p>The motivation behind DDoS attacks and hacking of the system is not clear, at least for me. As a non-profit company, Internet Archive is unlikely to have an overwhelming amount of money, sufficient for establishing a reliable cybersecurity protection. This exact reason ruins any suggestions about the ransom demand for non-disclosure of the hack.<\/p>\n<h2>Archive.org Gives No Answer<\/h2>\n<p>Despite the massive number of affected users, Internet Archive did not come out with any comments about the situation or their further steps. And it is hard to explain by saying it is too soon to say anything: a security breach allegedly happened in late September, with the <strong>latest records from the database dating September 28, 2024<\/strong>. They should be aware about the issue for quite some time now, and considering the number of people exposed in that attack, the response should have been immediate.<\/p>\n<p>For people who had their accounts on Archive.org, the best solution would be to track HIBP website updates. They already claimed receiving the <a href=\"https:\/\/gridinsoft.com\/data-breaches\">leaked info<\/a>, and say about being ready to index it and make it publicly available. With a search by either a username or an email address, you will get the information on what exact information was exposed in your case.<\/p>\n<p style=\"padding-top:15px;padding-bottom:15px;\"><a href=\"\/download\/antimalware\" rel=\"nofollow\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"\/blogs\/wp-content\/uploads\/2022\/07\/env02.webp\" alt=\"Archive.org Hacked, Exposing Over 31 Million Users\" width=\"798\" height=\"336\" class=\"aligncenter size-full\" title=\"\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Archive.org, a worldwide known archive of the entire Internet, suffered a huge data breach. The website was defaced, with a message from hackers saying that the site was badly secured and user data will soon be available at Have I Been Pwned service. The service already confirmed receiving the leak, with as much as 6.4GB [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":27590,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15],"tags":[619,697],"class_list":{"0":"post-27578","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"tag-cybersecurity","9":"tag-data-breach"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/10\/internet-archive-hacked-featured.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/27578","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=27578"}],"version-history":[{"count":7,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/27578\/revisions"}],"predecessor-version":[{"id":27596,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/27578\/revisions\/27596"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/27590"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=27578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=27578"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=27578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}