The Internet Archive was breached again (this time on its email support platform Zendesk), after attackers stole exposed GitLab authentication tokens.

It is said that the organization was breached because it did not perform proper token rotationon the stolen authentication tokens.
“It is disappointing to see that while being notified of the breach weeks ago, IA has not taken appropriate steps to rotate multiple API keys that were exposed in their gitlab secrets,” the attackers said in an email.
“As evidenced by this message, there is a Zendesk token with access permissions to 800,000+ support tickets sent to info@archive.org since 2018.“.
See also: USDoD: Hacker behind National Public Data breach arrested
“Whether you're trying to ask a general question or request your website be removed from the Wayback Machine, data is now in the hands of some random guy. If not mine, then someone else's.“.
The email headers in these emails pass all DKIM, DMARC, and SPF authentication checks, proving that they were sent from an authorized Zendesk server at 192.161.151.10.
As BleepingComputer learned, one of the recipients of these emails said he had to upload his personal IDwhen requesting the removal of a page from the Wayback Machine.
Attackers may now have access to these attachments as well, depending on the API access they had in Zendesk.
These emails come after BleepingComputer repeatedly tried to alert the Internet Archive that its source code was stolen via a GitLab authentication token that was exposed online for nearly two years.
GitLab authentication tokens exposed
On October 9, BleepingComputer reported that the Internet Archive was hit by two separate attacks: a data breach that affected 33 million users and a DDoS attack by a pro-Palestinian group called SN_BlackMeta.
See also: Intesa is being investigated for a data breach by a former employee
While both attacks occurred around the same time, they were carried out by different hacking groups. Many have reported that they were the same attackers. However, the SN_BlackMeta group was behind the DDoS attack.
The attacker behind the actual Internet Archive data breach contacted BleepingComputer, via an intermediary, to claim responsibility. According to him, the initial Internet Archive breach began with the discovery of an exposed GitLab configuration file on one of the organization’s development servers (services-hls.dev.archive.org). BleepingComputer confirmed that this token had been exposed since at least December 2022.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The threat actor says that this GitLab configuration file contained an authentication token that allowed him to download the Internet Archive source code.
The hacker says that this source code contained additional credentials and authentication tokens, including credentials for the Internet Archive's database management system. This allowed the threat to download the organization's user database and further source code, while also being able to modify the website.

The attacker claimed to have stolen 7TB of data from the Internet Archive , but did not share any samples as proof. However, we now know that the stolen data also included API access tokens for the Internet Archive's Zendesk support system
Following the Internet Archive breach, many conspiracy theories have emerged. Some said Israel did it, others the United States government, while others said it was done by companies due to their battle with the Internet Archive over copyright infringement.
See also: Gryphon Healthcare and Tri-City reveal significant breaches
However, the Internet Archive does not appear to have been hacked for political reasons. There are many hackers who traffic in stolen data. They may be blackmailing the victim for money, selling data to other threat actors, or simply collecting data for other attacks.
In the case of the Internet Archive, the attackers likely wanted to boost their reputation in the cybercrime community, because it is a popular organization.
The leaked database can now be exchanged between cybercriminals and we will probably see it circulating for free on some hacking forum.
The Internet Archive breach highlights the importance of maintaining good cybersecurity practices and being aware of potential security risks when using online services. This incident serves as a reminder that no website or service is completely immune to cyberattacks , and it is important for individuals to take proactive steps to protect their personal data.
Sites like the Internet Archive should take care to protect user data by regularly updating their security protocols and implementing measures such as encryption and regular security checks.
Source: www.bleepingcomputer.com
