Internet Archive Users Get Emails from Hackers Criticizing Unfixed Security Flaw! πŸ“§

Summary:

  1. Email Communication from Hackers
    Users of the Internet Archive started receiving emails that appear to come from hackers, criticizing the organization for not fixing a security vulnerability related to stolen API tokens.

  2. Breached Security Details
    The hackers claim they accessed a Zendesk token that allows them to view over 800,000 support tickets dating back to 2018, affecting users’ private information.

  3. History of the Breach
    The breach began with an exposed GitLab configuration file on the Internet Archive’s server, allowing hackers to download the source code and access sensitive credentials.

  4. Massive Data Theft
    The threat actor claims to have stolen 7TB of data, including the user database, and has expressed frustration at the Internet Archive’s lack of response and action regarding security issues.

  5. Concerns Over Future Security
    The incident raises concerns about ongoing vulnerabilities, as the hackers indicate that the stolen data is likely being shared within hacking communities and could be leaked publicly in the future.

Read more at: BleepingComputer

1 Like