Internet Archive Cyberattack Exposes Personal Data of 31 Million Users

SUMMARY

  • 31 million users affected by a cyberattack on the Internet Archive.
  • Attack resulted from a DDoS incident, exposing sensitive data via the JS library.
  • The platform has resumed operations in read-only mode while enhancing security measures.

The Internet Archive, a prominent digital library housing millions of free books, movies, music, and websites, has recently suffered a significant cyberattack. A breach notification revealed that personal data from 31 million users has been compromised, raising critical concerns about data security in today’s digital landscape.

On October 9, 2024, the Internet Archive experienced a Distributed Denial-of-Service (DDoS) attack that incapacitated its servers for several days. The breach occurred via their JavaScript (JS) library, which exposed sensitive user information, including email addresses, usernames, and passwords. Following the attack, founder Brewster Kahle confirmed the security breach on social media, stating that the organization had undertaken measures to mitigate the attack, including DDoS scrubbing, disabling the JS library, and enhancing security protocols.

The ramifications of this breach are severe, putting all 31 million affected accounts at risk. The exposed data could be exploited by fraudsters for phishing attempts and other malicious activities, particularly given the advancements in AI that enable the generation of convincing emails and messages. Users are urged to check their compromised information using Have I Been Pwned? (HIBP), a site dedicated to helping individuals ascertain whether their data has been leaked.

This incident underscores the urgent need for stronger cybersecurity measures, particularly for organizations managing sensitive data.

After the attack, the Internet Archive has implemented additional security measures and has restored its services, though currently in read-only mode. The Wayback Machine, which offers access to 916 billion web pages, remains operational, except for the latest versions of archived pages. The organization is actively working to address vulnerabilities to prevent future incidents.