The Internet Archive, a nonprofit digital library, has suffered a serious data leak that compromised the account information of 31 million users. The organization is also fighting against an ongoing DDoS attack that restricts access to its services.
Important findings
- 31 million accounts affected, including email addresses and hashed passwords.
- DDoS attacks have hindered access to the site since October 10.
- The attacks could be related to the data leak.
- Users should change their passwords as soon as the website is accessible again.
Details about the data leak
On October 10, 2024, it became known that the Internet Archive, which provides free access to archived websites and other materials, was the victim of a massive data leak. Affected account information includes email addresses, usernames and hashed passwords. Through the database "Have I Been Pwned" the users were informed about the incident.
Of the 31 million affected accounts, more than half had already published their email addresses in previous data leaks. This suggests that many users may already be at risk.
DDoS attacks and their effects
In addition to the data leak, the Internet Archive is facing a DDoS attack that has continued since 10 October. This type of attack overloads the organisation’s servers and makes the website inaccessible to users. The group “Sn_darkmeta” claimed responsibility for the attacks and said it was protesting US support for Israel.
Response to the incident
Troy Hunt, the developer of "Have I Been Pwned", received a copy of the stolen data on September 30 and informed the Internet Archive on October 1. The organization confirmed receipt of the data, but an official notification to the users is still pending. Hunt expressed understanding for the situation as the organization is under considerable pressure.
Security of the hashed passwords
User passwords were hashed with the bcrypt algorithm, which is considered secure. Unlike faster algorithms, bcrypt is designed to make it harder to crack passwords. However, professionals recommend that users change their passwords to minimize potential risks.
Conclusion
The Internet Archive incident is a serious warning for all users of digital services. It is crucial to use strong, unique passwords and change them regularly. The organisation faces the challenge of ensuring user security while combating the ongoing DDoS attack. Users should remain vigilant and protect their account information.
Sources
- Internet Archive Data Breach Exposes 31 Million Accounts, GovInfoSecurity.



