Change your passwords: Attackers claim a 'catastrophic security breach' of the Internet Archive, with 31 million emails and hashed passwords captured

Archive.org, a donation driven non-profit that digitizes out-of-copyright books at U of T, has such little funding that they will have to lay off 2/3 of the 35-strong staff by August 12 unless more money comes in. July 8, 2011
(Image credit: Carlos Osorio/Toronto Star via Getty Images)

The Internet Archive—the online repository of, well, pretty much everything—is under attack. It's been hit by a series of DDOSes that have rendered the site essentially unusable since Wednesday, with the non-profit's engineers scrambling to fend off the assault, upgrade security, and keep users informed all at the same time.

None of which, alarmingly, is the worst part. If you try to go to the site at time of writing, you'll just find an error page, but visitors yesterday were greeted by a pop-up reading "Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!"

HIBP means Have I Been Pwned, a site you can use to check if your emails and passwords have been leaked in any of the data breaches that happen with disconcerting regularity online. In other words: The Archive's attackers are claiming to have nicked the deets for around 31 million accounts as part of their campaign, a breach which has since been confirmed by Archive founder Brewster Kale and HIBP's Troy Hunt (via Bleeping Computer).

"What we know:" wrote Kale earlier today, "DDOS attack–fended off for now; defacement of our website via JS library; breach of usernames/email/salted-encrypted passwords." The bad news is that you have an Internet Archive account, your username and email could well have been captured by the site's attackers.

The good news is that the version of your password they've gotten hold of is encrypted. Don't use that as an excuse to rest on your laurels, though: You should absolutely change your Archive password as soon as you can—and change it anywhere else you use that password, too.

Since the attack, Kale says that the Archive has "Disabled the JS library" used to access the site and serve the earlier pop-up, and that it is "scrubbing systems, upgrading security." Unfortunately, there's not much the site has been able to do about the DDOS attacks. Less than an hour before I wrote this, Kale posted that "DDOS folks are back and knocked Archive.org and Openlibrary.org offline," and that the site is "being cautious and prioritizing keeping data safe at the expense of service availability."

It's not entirely clear just yet who is behind the attack or what their reasons are. An account on X going by the name SN_Blackmeta—claiming to be located in "Old Rus, Novgorod Oblast"—has claimed responsibility, saying it was attacking the Archive "because the archive belongs to the USA," whose "horrendous and hypocritical government supports the genocide that is being carried out by the terrorist state of 'Israel.'" It's worth noting that the Archive has no notable ties to the US government beyond being based in America.

Of course, whether that account actually has ties to the Archive's attackers or is just opportunistically claiming responsibility, and whether its provided reasons for doing so are its actual reasons, is far from clear.

It's one more problem the Archive doesn't need. Earlier this year, the site was forced to remove half a million books from its lending library after losing a landmark copyright lawsuit against a number of publishing companies. The Archive is appealing the ruling, but I have to imagine that Brewster Kale and co have a world-historic headache right now after a terrible 2024.

Joshua Wolens
News Writer

One of Josh's first memories is of playing Quake 2 on the family computer when he was much too young to be doing that, and he's been irreparably game-brained ever since. His writing has been featured in Vice, Fanbyte, and the Financial Times. He'll play pretty much anything, and has written far too much on everything from visual novels to Assassin's Creed. His most profound loves are for CRPGs, immersive sims, and any game whose ambition outstrips its budget. He thinks you're all far too mean about Deus Ex: Invisible War.

Read more
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
3D illustration of a grid of black cpus with different IoT symbols, representing a botnet concept
Cloudflare claims to have mitigated biggest DDoS attack on record with requests flying in from 5,500 IP addresses per second
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
Latest in Gaming Industry
SUQIAN, CHINA - OCTOBER 6, 2024 - Illustration Tencent's plan to buy Ubisoft, Suqian, Jiangsu province, China, October 6, 2024. (Photo credit should read CFOTO/Future Publishing via Getty Images)
Ubisoft and Tencent are forming a new company that will take control of its most successful franchises: Assassin's Creed, Far Cry, and Rainbow Six
Kinich, a character in Genshin Impact, stands prepared to brawl with an enemy.
'Diabolical': Genshin Impact's English cast gives new VO the cold shoulder after he frames replacing a striking actor as an 'opportunity to carry the flame'
PC Gamer magazine issue 408 Doom: The Dark Ages
PC Gamer magazine's new issue is on sale now: Doom: The Dark Ages
Two brightly colored stormtroopers dressed like Run-DMC stand in front of PAX Australia's WELCOME HOME banner.
Tickets for PAX Australia 2025 are on sale now
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
Monster Hunter Wilds' stockpile master studying a manifest
As layoffs and studio closures continue to deathroll the western AAA industry, analyst points out 5 of 8 major Japanese companies hit all-time share prices this year
Latest in News
kingdom come deliverance 2 pacifist run
'Medieval Batman' completes Kingdom Come: Deliverance 2 pacifist playthrough with zero kills and 535 knockouts
SUQIAN, CHINA - OCTOBER 6, 2024 - Illustration Tencent's plan to buy Ubisoft, Suqian, Jiangsu province, China, October 6, 2024. (Photo credit should read CFOTO/Future Publishing via Getty Images)
Ubisoft and Tencent are forming a new company that will take control of its most successful franchises: Assassin's Creed, Far Cry, and Rainbow Six
A motley crew riding out in point-and-click adventure Rosewater
Promising '90s style point-and-clicker Rosewater rides out today, featuring trail-worn cowpoke authors and weird alt-universe science
A girl cheering in Everybody's Golf Hot Shots.
My favourite, most underrated anime golf game series is actually getting a PC entry for the first time in its nearly 30-year history
A shock trap transformed into a Lego brick in Monster Hunter Wilds.
A modder keeps turning Monster Hunter traps into Lego bricks so that the monsters will know true pain, and they've just done it again
live action Jimbo the Jester from Balatro holding a playing card and addressing the camera
You've probably been pronouncing Balatro wrong all along, but 'it's kind of a gif/jif situation'