Cyberattack on Internet Archive Puts 31 Million Users' Data at Risk
Numerous internet hacking incidents have been occurring, and it is indeed a cause for concern. These attacks target the personal information and passwords of millions of users worldwide, making them susceptible to abuse and misuse by fraudsters and other malicious parties.
An attack of this magnitude recently occurred at The Internet Archive (www.archive.org), a website that serves as a repository of historical content. Its most notable feature is The Wayback Machine, which stores snapshots of websites over the years. It also hosts the Open Library, a collection of books that have been digitized and made available online.
According to The Verge, the Internet Archive’s founder Brewster Kahle confirmed the DDOS (Distributed Denial of Service) attack on Wednesday, October 10, in the United States.
ALSO READ
NAIA’s Internet Is One of the Worst in Southeast Asia, a Report Says
It’s Time to Pass the Bill Mandating Refunds Each Time There’s an Internet Outage
The attack inserted a pop-up message that activates once a user accesses the site, saying:
“Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!”
HIBP, the “Have I Been Pwned” website, allows users to check if their personal information has been compromised. HIBP confirmed that they received a file containing data from compromised accounts. The figures suggest that the data of 31 million users has been acquired through the attack.
Sometime after, the site became inaccessible and remains down at the time of this writing.
Kahle reported that an X account under the name SN_BlackMeta claimed responsibility for the attack, also mentioning that another attack was planned for the following day. He also said that the attack had been "fended off for now" and identified the backdoor for the incursion as the JS (JavaScript) library component. They have since disabled the library and upgraded security.
Kahle also mentioned that SN_BlackMeta has been linked to a pro-Palestinian hacktivist movement and is believed to be responsible for an earlier attack on a financial entity in the Middle East. Whether this is related to the recent conflicts in the Middle East has yet to be established.
For now, users are advised to check HIBP and other identity theft checker sites to see if their data is part of the compromised batch. They should also change their passwords and strengthen access methods for their accounts.