Internet Archive Gets Pummeled in Round 2 Breach

Teilen:

This latest breach was through Zendesk, a customer service platform that the organization uses.

Just a few days after the Internet Archive told the public it was getting back on its feet after a data breach and a barrage of distributed denial-of-service (DDoS) attacks forced it to go offline, the digital library website is once again in trouble.

Unknown bad actors have allegedly claimed access tokens to the archive’s Zendesk implementation, using them to send a mass email on Oct. 20 to those who tried to interact with the archive’s platform.

“Internet Archive did not secure its authentication tokens, which enabled unauthorized access to their Zendesk instance,” a Zendesk spokesperson told Dark Reading. “It’s important to note that there is no evidence this was a Zendesk issue and that Zendesk did not experience a compromise of its platform. We have since worked together with Internet Archive to secure their account.”

The hacker’s email to archive users began as follows:

“It’s dispiriting to see that even after being made aware of the breach two weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their GitLab secrets,” the hacker stated. “As demonstrated by this message, this includes a Zendesk token with perm[ission]s to access 800K+ support tickets sent to [email protected] since 2018.” 

The email continued, “Whether you were trying to ask a general question or requesting the removal of your site from the Wayback Machine — your data is now in the hands of some random guy. If not me, it’d be someone else.”

Though it can’t be said for certain, Chris Hickman, chief security officer (CSO) of Keyfactor, said the hacker may not have serious malicious intent, but instead wants to prove a point: that those in charge of the Internet Archive must be more proactive in protecting its network from those who would do much worse.

“This is a security oversight as tokens that are not rotated regularly have longer lifespans, increasing the window of opportunity for attackers to steal and misuse them,” Hickman wrote in an emailed statement to Dark Reading. “If a token is not rotated correctly, it might expire, leading to authentication failures for legitimate users. If a malicious actor obtains an unrotated token, they could use it to gain unauthorized access to systems or services, leading to service disruptions and customer frustration, damaging a company’s reputation and bottom line.”

The organization hasn’t made any public comments regarding the latest breach, but it did request donations last week to help support its endeavors of promoting open access to knowledge resources.

Dark Reading

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:14 pm, Juli 4, 2025
Wetter-Symbol 21°C
L: 19° | H: 22°
overcast clouds
Luftfeuchtigkeit: 58 %
Druck: 1021 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
19° | 22°°C 0.38 mm 38% 12 mph 85 % 1021 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
17° | 21°°C 1 mm 100% 12 mph 83 % 1010 mb 0 mm/h
Mo. Juli 07 10:00 pm
Wetter-Symbol
12° | 22°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Di. Juli 08 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 10 mph 71 % 1020 mb 0 mm/h
Mi. Juli 09 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 8 mph 77 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 10 mph 57 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 17°°C 0 mm 0% 10 mph 59 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
16° | 16°°C 0.38 mm 38% 9 mph 77 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 10 mph 72 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 11 mph 70 % 1015 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 12 mph 75 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 12 mph 78 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 85 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,705.13
-1.75%
Ethereum(ETH)
€2,122.27
-3.91%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.89
-2.29%
Solana(SOL)
€125.05
-3.84%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.138288
-5.62%
Shiba Inu(SHIB)
€0.000009
-4.59%
Pepe(PEPE)
€0.000008
-5.56%
Nach oben scrollen