Mashable 2024年10月11日
Internet Archive data breach: Hacker claims to ‘See 31 million of you' on Have I Been Pwned
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

互联网档案馆近期遭受黑客攻击,不仅面临DDoS攻击导致长时间无法访问,还出现数据泄露,3100万用户的信息被盗。该机构的数字图书管理员表示正优先确保数据安全,DDoS攻击的实施者SN-Blackmeta称因美国对以色列的支持而发动攻击,但该机构实际为独立非营利组织。

🥳互联网档案馆是一个保存数字媒体存档的非营利组织,通过Wayback Machine保存网站等的存档版本,但本周初开始遭受DDoS攻击,导致长时间无法访问。

😱3100万互联网档案馆用户的电子邮件、屏幕名称和加密密码在数据泄露中被盗,目前尚不清楚数据泄露与DDoS攻击是否有关。

🤔SN-Blackmeta声称对DDoS攻击负责,称因美国对以色列的支持且认为互联网档案馆属于美国而发动攻击,但很多人指出该机构是独立非营利组织,与美国政府无关。

The Internet Archive is currently under attack from hacker groups. And, it seems these bad actors have been able to access sensitive data for millions of the Internet Archive's users.

The non-profit Internet Archive, which keeps archived versions of digital media including websites via The Wayback Machine, has been suffering from distributed denial of service (DDoS) attacks since the beginning of the week. These attacks have resulted in prolonged inaccessibility.

"@internetarchive is being cautious and prioritizing keeping data safe at the expense of service availability," posted Internet Archive digital librarian Brewster Kahle on his X account.

However, the DDoS attacks aren't the only thing the Internet Archive has to worry about. It appears that the Internet Archive has been unable to keep at least some of its data safe as it undergoes attacks from threat actors. 

Emails, screen names, and encrypted passwords for 31 million Internet Archive users have been stolen in a data breach. At this time, it's unclear if the data breach and the DDoS attacks are related.

Internet Archive hacked

Along with the downtime related to the DDoS attacks, social media users began noticing a pop-up prompt on the Internet Archive's website on Wednesday.

"Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach?" read the prompt. "It just happened. See 31 million of you on HIBP!"

HIBP refers to the website Have I Been Pwned, a website that notifies users if their data was involved in a data breach.

According to Bleeping Computer, Have I Been Pwned founder Troy Hunt confirmed to the outlet that they had received a 6.4GB SQL database file which includes users' "email addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data."

Hunt has been able to confirm the legitimacy of the data. Based on the timestamp on the hacked information, it appears that it was likely stolen on September 28, 2024. Hunt said that he contacted the Internet Archive before loading the data into the Have I Been Pwned service. He has not yet heard back.

A group known as SN-Blackmeta has claimed responsibility for the DDoS attack. Again, its unclear if they are involved in the data breach. The group said that it carried out the DDoS attack because of the United States' support for Israel and that the Internet Archive "belongs to the USA." Many social media users were quick to point out that the Internet Archive is an independent non-profit organization and is not affiliated with the U.S. government.

Mashable has reached out to the Internet Archive for more information on the attacks and will update this post when we hear back.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

互联网档案馆 DDoS攻击 数据泄露 SN-Blackmeta
相关文章