Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurebreach-disclosure-notificationoperational-disruptionhacktivist-operation

Internet Archive Breach Exposed 31 Million Accounts Amid Site Defacement and DDoS

Updated 28d agoFirst seen Mar 27, 20262 sources

Internet Archive confirmed a breach that exposed data tied to 31 million user accounts after attackers displayed a malicious JavaScript pop-up on the site announcing the intrusion. According to reporting validated by security researcher Troy Hunt and others, the stolen data dated to September 2024 and included email addresses, screen names/usernames, bcrypt password hashes, and other system data from the organization's digital library platform.

The disclosure unfolded as Internet Archive was also contending with intermittent distributed denial-of-service attacks that disrupted availability and a site defacement linked to a compromised JavaScript library. Founder Brewster Kahle said security upgrades were underway; hacktivist group BlackMeta claimed responsibility for the DDoS activity, while the actor behind the underlying data theft was not identified. The breach was later cataloged by Have I Been Pwned as affecting 31 million records.

Share:
Internet Archive Breach Exposed 31 Million Accounts Amid Site Defacement and DDoS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Oct 9, 20242y ago

Have I Been Pwned adds the Internet Archive breach

Have I Been Pwned listed the Internet Archive breach in March 2026, documenting the incident as affecting 31 million records from the September 2024 compromise. The entry summarized the exposed data types, including email addresses, screen names, and bcrypt password hashes.

DDoS attacks disrupt Internet Archive services

Around the same time as the breach disclosure in early October 2024, Internet Archive faced intermittent distributed denial-of-service attacks that forced services offline. Hacktivist group BlackMeta claimed responsibility for the DDoS activity, though not for the underlying data breach.

Oct 7, 20242y ago

Internet Archive confirms breach after website defacement

On October 7, 2024, Internet Archive confirmed the breach after attackers displayed a malicious JavaScript pop-up on its website announcing the incident. Founder Brewster Kahle also said the site had been defaced via a JavaScript library and that security upgrades were underway.

Oct 6, 20242y ago

Internet Archive is notified of the breach

On October 6, 2024, Troy Hunt notified Internet Archive about the stolen data. This appears to have been a direct disclosure step before the organization publicly confirmed the incident.

Oct 5, 20242y ago

Troy Hunt reviews the breach data

Hunt reviewed the stolen Internet Archive data on October 5, 2024, confirming it contained 31 million unique email addresses and associated account information. This analysis helped establish the breach as legitimate.

Sep 30, 20242y ago

Troy Hunt receives stolen Internet Archive data

Security researcher Troy Hunt said he received the stolen dataset on September 30, 2024. The data related to the Internet Archive breach and later helped validate the scope of the exposure.

Sep 28, 20242y ago

Internet Archive suffers breach exposing 31 million records

In September 2024, Internet Archive experienced a data breach affecting its digital library systems. The stolen data included about 31 million records with email addresses, screen names or usernames, bcrypt password hashes, and other system data.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Organizations
1 linked
Internet Archive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.