In October 2024 the Internet Archive was hit by a series of incidents: a defacement of its site, the theft of user records covering around 31 million accounts, and separate denial-of-service attacks that took the service offline. Reported exposed fields include email addresses, screen names and bcrypt-hashed passwords.
Three Incidents, Not Obviously One
The defacement, the data theft and the denial of service were reported together because they happened together. That does not make them a single operation, and the Archive did not present them as one.
The same overlap appeared at Estée Lauder in 2023, where two unrelated ransomware operations arrived in the same window. An organisation dealing with a visible attack should not assume the visible attack is all of it.
A Library Is Not A Bank And Is Attacked Anyway
The Internet Archive is a non-profit that preserves the web. It holds no payment data and offers nothing to extort, which makes the defacement and the denial-of-service look like ends in themselves.
The user records still matter. Hashed passwords are a cost problem for an attacker rather than a barrier, and the accounts they unlock elsewhere are the point. Graded medium: the 31 million figure comes from the stolen dataset rather than from the Archive.
Compiled from public reporting and the Archive’s statements, listed below. The 31 million figure derives from the stolen dataset. Whether the concurrent incidents share an operator has not been established. Corrections: corrections@forensicpost.com.
- Internet Archive hacked, data breach impacts 31 million usersBleepingComputer