Cyber Security

Internet Archive Breached Again, Hackers Exploited Unrotated API Tokens

The Internet Archive has fallen victim to another cyberattack, marking the third major security incident in October 2024.

On October 20, hackers successfully exploited unrotated API tokens to gain unauthorized access to the organization’s Zendesk support platform, potentially compromising sensitive user data.

This latest breach follows two previous attacks earlier in the month, highlighting the nonprofit digital library’s ongoing security challenges.

The hackers were able to access and potentially download support tickets dating back to 2018, which may include personal identification documents submitted by users.

Join ANY.RUN's FREE webinar on How to Improve Threat Investigations on Oct 23 - Register Here 

The root cause of this breach appears to be the Internet Archive’s failure to rotate API tokens for its Zendesk system despite being aware of previous security vulnerabilities. This oversight allowed attackers to maintain access to the support platform, putting user data at risk.

The Internet Archive, founded in 1996 by Brewster Kahle, is a vital resource for researchers, historians, and the general public. It is best known for its Wayback Machine, which preserves snapshots of websites over time.

As of September 2024, the Archive held over 42.1 million print materials, 13 million videos, 1.2 million software programs, and 866 billion web pages.

The series of attacks began on October 9, when hackers exploited an exposed GitLab token to access the Archive’s source code and user database, affecting 31 million users.

This initial breach was followed by a Distributed Denial of Service (DDoS) attack, further disrupting the organization’s operations.

Cybersecurity experts have expressed concern over the repeated breaches and the Archive’s inability to secure its systems effectively.

The Internet Archive’s founder, Brewster Kahle, has acknowledged the security breaches and stated that the organization is working to enhance its security measures.

However, the repeated incidents have raised questions about the Archive’s ability to protect its vast data.

As the Internet Archive works to address these security issues, users are advised to remain vigilant and monitor their accounts for any suspicious activity.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago