pwshub.com

Internet Archive leaks user info and succumbs to DDoS

The Internet Archive had a bad day on the infosec front, after being DDoSed and exposing user data.

On Wednesday afternoon US time the outfit’s digital library Brewster Kahle revealed a DDoS attack had made the site unavailable. The Register understand the outage may have lasted up to five hours, during which time visitors saw only a notification of the incident.

While that was happening, data leak notification service haveibeenpwned (HiBP)posted news of a leak that saw 31,081,179 users’ accounts exposed. Register staff received mails from HIBP that state “The breach exposed user records including email addresses, screen names and bcrypt password hashes.”

Kahle later confirmed the leak , writing that the service has detected “defacement of our website via JS library; breach of usernames/email/salted-encrypted passwords.”

The org has disabled the JS library, and is “scrubbing systems , upgrading security.”

Kahle offered no detail beyond that but promised to “share more as we know it.”

It is unclear if the DDoS and breach are linked.

The Register sought comment from the Archive but had not received a response at the time of publication.

  • Internet Archive blames 'environmental factors' for overnight outages
  • Of course the Internet Archive’s digital lending broke the law, appeals court says
  • Google flushes cached search results forever
  • Bank of America app glitch zeroes out people's balances

The two incidents continue an unhappy 2024 for the Internet Archive, which has lost a case regarding its right to lend digital assets, gone offline due to power failures, and endured other disruptive DDoS events. ®

Source: theregister.com

Related stories
1 month ago - Background check company National Public Data admitted it exposed information like phone numbers, addresses and Social Security numbers to hackers.
1 month ago - Resources hosted at Tencent Cloud involved in Cobalt Strike campaign Chinese web champ Tencent's cloud is being used by unknown attackers as part of a phishing campaign that aims to achieve persistent network access at Chinese entities.…
1 month ago - That's what they want you to think — It's "actually a real company in the Boston area"—or is that just a...
1 month ago - Names, addresses, Social Security numbers, more all out there A Florida firm has all but confirmed that millions of people's sensitive personal info was stolen from it by cybercriminals and publicly leaked.…
1 month ago - The third iOS 18.1 developer beta brings Apple Intelligence, as well as several bug fixes.
Other stories
2 hours ago - New pharmacies are coming to 20 more cities, allowing about half the US Amazon Pharmacy customer base access to same-day medication delivery.
2 hours ago - Archive.org, possibly one of the only entities to preserve the entire history of the Internet, was recently compromised in a hack that revealed data...
3 hours ago - Breathe easier on the last day of Amazon's Prime Day event, with up to 40% off Molekule Air Purifiers. Amazon Prime members can qualify for even deeper discounts.
3 hours ago - These still-live Prime Day deals can help you optimize your work-from-home setup while saving you big bucks.
3 hours ago - The best water filter leave your water tasting crisp and clean. Our favorite water filter pitchers from ZeroWater do just that -- and they're 30% off for the last few hours of Prime Day.