Popular digital archive, ‘The Wayback Machine’ (an initiative of the Internet Archive) has allegedly suffered a massive data breach, with over 31 million records containing sensitive information being stolen via a user authentication database.
On Octover 9, vistitors to the ‘The Wayback Machine’s’ site, were greeted by a JavaScript alert, telling users “see 31 million of you on HIBP!”
HIBP refers to the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service.
Hunt later confirmed that HIBP had received a large file nine days prior containing the compromised data. This file, named “ia_users.sql,” was 6.4GB and included not only email addresses and screen names but also timestamps for password changes and Bcrypt-hashed passwords. Hunt was able to validate the data by cross-referencing it with user accounts.
Hunt reached out to several users whose data had been exposed, including cybersecurity researcher Scott Helme, who confirmed that his Bcrypt-hashed password matched the one stored in his password manager. However, questions remain about how the hackers infiltrated the Internet Archive’s systems and whether any additional sensitive information was stolen.
The most recent timestamp on the stolen records is September 28th, 2024, likely when the database was stolen.
Recommended reading
- ICO Issues New Compliance Audit Framework
- Northern Ireland Police Service Fined £750K After Data Breach
- Which Data Breaches Had Everyone Talking This Year?
The data will soon be added to HIBP, allowing users to enter their email and confirm if their data was exposed in this breach.
Shortly after the breach was disclosed, the Internet Archive suffered a Distributed Denial of Service (DDoS) attack, claimed by the hacktivist group “BlackMeta.” The attackers left a defaced message and a JavaScript alert on the site, which was eventually taken offline, with users directed to social media for updates. By the evening of October 9, the website remained mostly inaccessible.
Brewster Kahle, a leader at the Internet Archive, addressed the situation on X (formerly Twitter), explaining that the compromised JavaScript library was disabled and security upgrades were underway. The breach has raised concerns about cybersecurity at the Archive, as millions of users’ data may have been exposed. Users are encouraged to check their information and update passwords.





