EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/internet-archive-breach-2024
074/430

File EL-0357HighResolvedData Breach / Credential Theft

Internet Archive Data Breach

Also filed as Wayback Machine Defacement · ia_users.sql Leak

The Internet Archive suffered a major data breach and website defacement in late 2024. The attackers leaked a database containing 31 million user records, including email addresses and password hashes. The incident was accompanied by a massive Distributed Denial of Service (DDoS) attack that significantly disrupted the Wayback Machine service.

  • #internet-archive
  • #wayback-machine
  • #data-breach
  • #credential-theft
  • #hactivism
  • #sql-leak
Notoriety7/10
Event
28 Sept 2024
Disclosed
9 Oct 2024
Target
Internet Archive
Actor
SN_Blackmeta
Scale
31.0M people
Status
Resolved

01Summary

The breach was publicly disclosed on October 9, 2024, following a hacktivist communique from SN_Blackmeta. The attackers successfully exfiltrated a file named `ia_users.sql`, which contained the credentials for approximately 31 million registered users. This database included fields for email, screen name, and password hashes stored using Bcrypt. Beyond the data theft, the attackers also defaced the highly visible Wayback Machine service and launched a massive DDoS campaign. The group claimed their motivation was anti-US imperialism, targeting the Internet Archive as a US-based institution, thereby combining data theft with significant operational disruption.

02Background

The Internet Archive is a non-profit digital library dedicated to preserving human knowledge and digital culture. Its Wayback Machine is a globally recognized service that archives snapshots of websites, making it a critical piece of global digital infrastructure. The incident capitalized on the Archive's high public profile and its role in preserving historical data.

03Key revelations

  1. 01The compromise of 31 million user accounts' credentials.
  2. 02The exposure of password hashes (Bcrypt), necessitating immediate password changes for all users.
  3. 03The successful execution of a massive DDoS attack that disrupted the Wayback Machine for weeks.

04Technical analysis

The attack vector likely involved exploiting a vulnerability in the Archive's user authentication or database layer, allowing the attackers to dump the user credentials. The leaked file, `ia_users.sql`, confirms the exfiltration of structured user data. The use of Bcrypt for password hashing indicates standard industry practice, but the leak itself compromises the integrity of the user base by forcing mandatory password resets and vigilance against credential stuffing.

Attack vector
Unspecified (Likely SQL Injection or API Exploitation)
Attack method
Data Exfiltration and Denial of Service (DDoS)
Exfiltration
Database Dump/SQL Exfiltration
Tool / malware
ia_users.sql (Database Dump)
Malware type
Stealer/Database Dump

Vulnerabilities exploited

  • Unspecified Database Vulnerability

MITRE ATT&CK techniques

  • T1566.001
  • T1499

05Threat actor

SN_Blackmeta is a self-proclaimed hacktivist group that uses its communiques to announce cyberattacks. Their stated motivation is political, often targeting institutions they deem aligned with US imperialism, making their actions ideologically driven rather than purely financially motivated.

Aliases

  • Unknown Actor

MITRE groups

  • T1566.001

Attribution sources

  • SN_Blackmeta (Self-Claim)

06Victims and impact

Countries affected

  • USA

07Data exposed

Data types

  • emails
  • screen names
  • password hashes
  • user metadata

Notable documents

  • ia_users.sql

08Financial damage

Damage is primarily reputational and operational, requiring significant resources for user notification and system hardening.

09Timeline

  1. 2024-09-28Initial breach and data exfiltration occurred.
  2. 2024-10-09Hacktivist communique was published, announcing the leak and defacement.

10On the record

Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of a catastrophic security breach? It just happened.

SN_Blackmeta, Displayed as a JavaScript alert on archive.org homepage, mocking the Archive's security posture.

11Reaction and fallout

Public reaction

The public reaction was characterized by alarm regarding the scale of the data leak and the potential for identity theft. Users were immediately advised to change passwords and enable multi-factor authentication across all services.

Political impact

The incident highlighted the vulnerability of large, critical non-profit digital infrastructure to hacktivist action. It fueled ongoing debates regarding the security responsibilities of global digital preservation services.

Geopolitical consequences

The attack was framed within an anti-US imperialism narrative, suggesting that digital infrastructure in the US is a target for geopolitical hacktivism.

12Legal

No immediate legal action was reported, but the incident prompted calls for increased security auditing and compliance within the digital preservation sector.

13Aftermath

Policy changes

  • Increased emphasis on mandatory Multi-Factor Authentication (MFA) for large public platforms.

Security improvements

  • Mandatory rotation of database credentials and hardening of API endpoints.
  • Implementation of advanced DDoS mitigation services.

14Significance and legacy

Significance

This breach is significant because it demonstrates the vulnerability of massive, publicly accessible, non-commercial digital archives. It serves as a modern example of hacktivism combining data theft with operational sabotage (DDoS), making the impact both informational and physical (service disruption).

Legacy

The incident has increased scrutiny on the security practices of digital preservation organizations globally. It reinforces the need for robust, layered security defenses that account for both sophisticated cyberattacks and politically motivated disruption.

15Disclosure and media

Authentication
Self-claimed by attacker

16Field notes

  1. 01The leaked database contained password hashes using Bcrypt, which is a computationally intensive hashing algorithm designed to resist brute-force attacks.
  2. 02The attack combined a data breach (the leak) with a service disruption (the DDoS), maximizing both informational and operational damage.

17Resolution

The Internet Archive issued statements acknowledging the breach and advising users to treat the leaked credentials as compromised, urging immediate password changes and the adoption of unique, strong passwords.

18Sources

References

  1. [1]Hacktivist Communique (SN_Blackmeta)
  2. [2]Internet Archive Security Advisories
Fact sheetEL-0357

Dates

Event
28 Sept 2024
Started
28 Sept 2024
Ended
9 Oct 2024
Duration
11 days
Discovered
9 Oct 2024
Disclosed
9 Oct 2024
Ongoing
No

Target

Organisation
Internet Archive
Type
Technology Company
Sector
Digital Preservation/Non-Profit
Country
USA

Actor

Name
SN_Blackmeta
Type
Hacktivist Group
Motivation
Anti-US imperialism; disruption of US-based institutions.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

People
31,000,000
Records
31,000,000
Volume
6.4 GB
Sensitivity
Confidential
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.