Site navigation

Wayback Machine Breach Exposes Millions of Users

Graham Turner

,

Wayback Machine breach
The breach included Bcrypt-hashed passwords and sensitive user information.

Popular digital archive, ‘The Wayback Machine’ (an initiative of the Internet Archive) has allegedly suffered a massive data breach, with over 31 million records containing sensitive information being stolen via a user authentication database.

On Octover 9, vistitors to the ‘The Wayback Machine’s’ site, were greeted by a JavaScript alert, telling users “see 31 million of you on HIBP!”

HIBP refers to the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service.

Hunt later confirmed that HIBP had received a large file nine days prior containing the compromised data. This file, named “ia_users.sql,” was 6.4GB and included not only email addresses and screen names but also timestamps for password changes and Bcrypt-hashed passwords. Hunt was able to validate the data by cross-referencing it with user accounts.

Hunt reached out to several users whose data had been exposed, including cybersecurity researcher Scott Helme, who confirmed that his Bcrypt-hashed password matched the one stored in his password manager. However, questions remain about how the hackers infiltrated the Internet Archive’s systems and whether any additional sensitive information was stolen.

The most recent timestamp on the stolen records is September 28th, 2024, likely when the database was stolen.


Recommended reading


The data will soon be added to HIBP, allowing users to enter their email and confirm if their data was exposed in this breach.

Shortly after the breach was disclosed, the Internet Archive suffered a Distributed Denial of Service (DDoS) attack, claimed by the hacktivist group “BlackMeta.” The attackers left a defaced message and a JavaScript alert on the site, which was eventually taken offline, with users directed to social media for updates. By the evening of October 9, the website remained mostly inaccessible.

Brewster Kahle, a leader at the Internet Archive, addressed the situation on X (formerly Twitter), explaining that the compromised JavaScript library was disabled and security upgrades were underway. The breach has raised concerns about cybersecurity at the Archive, as millions of users’ data may have been exposed. Users are encouraged to check their information and update passwords.

Graham Turner

Sub Editor

Latest News

Cybersecurity

Manchester Airport Group Suffers Data Breach of Customer Info

AI Cybersecurity Editor's Picks Security

Google, Microsoft and OpenAI Call For Cyber Defence Push

Featured Finance

Final Extension Announced for Scottish Fintech Awards

Business

Business Confidence in Scotland Rises as Trading Outlook Climbs