Skip to main content
Blog
Blog

The Internet Archive Hack: How JavaScript fits in the picture

The Internet Archive, also known as The Wayback Machine, experienced a security breach yesterday. This was not the first time it had been ta

Oct 18, 2024 2 min read
the-internet-archive-hack-image-cover

TL;DR: Internet Archive JavaScript compromise

  • A browser-layer breach: The story got framed as a backend breach, but the visible payload was a taunting JavaScript popup running inside the browser, which is exactly the layer most security programs still have zero real visibility into today.
  • Free for non-profits: The breach exposed data for 31 million unique email addresses on Have I Been Pwned, and cside is offering its client-side monitoring free of charge to any non-profit organization that wants runtime browser protection.
  • Your evidence trail: If the archive researchers rely on to investigate other attacks can be defaced in-browser by attackers, your own evidence trail is not as solid as it looks, so decide who actually monitors your client-side layer today.

Short on time? See cside's in-browser Magecart and skimmer blocking. It covers everything below in one deployment.

What happened at the Internet Archive

The Internet Archive, known best for The Wayback Machine, experienced a security breach yesterday. This was not the first time it had been targeted.

A mocking JavaScript popup appeared, stating:

Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!

Mocking JavaScript popup left by attackers on the Internet Archive

HIBP, short for Have I Been Pwned?, is a site where users can check if their personal information has been compromised in a data breach. Troy Hunt, who runs HIBP, told BleepingComputer that he received a file days ago containing internal data for 31 million unique email addresses. He verified the data's authenticity by comparing it with a user's account details.

Have I Been Pwned listing of the Internet Archive breach data

The Internet Archive is an invaluable resource when researching cyberattacks. During our investigation into the Polyfill attack, we used it to uncover a fraudulent "Cloudflare Security Protection" tag.

Internet Archive snapshot of the polyfill.io homepage during the attack

It's disheartening to see non-profit organizations targeted by cybercriminals. While this incident involved a backend breach, no website is fully protected from the client-side attacks that we defend against.

As a result, we have decided to offer our services free of charge to any non-profit organization. Those that wish to use cside for their non-profit organizations will gain access to our advanced tools at no cost.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

Attackers used a JavaScript popup on archive.org to taunt visitors and likely abused a vulnerable client-side dependency to escalate access. The data of 31 million users was later confirmed leaked to Have I Been Pwned.

Researchers and journalists rely on archive snapshots to investigate breaches. When the archive itself is compromised, the evidence trail for other supply chain attacks, like Polyfill, becomes harder to verify.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead