Troy Hunt, creator of the compromised password-checking service 'Have I Been Pwned' (haveibeenpwned.com), received information about a leak of the user database from the organization Internet Archive (archive.org), which maintains an archive of website states and the largest library of digitized content. The attackers provided Troy with an SQL dump that includes accounts of 31 million users from archive.org. Additionally, a JavaScript code was injected into the archive.org site, resulting in a pop-up window displaying information about the breach.

A leak warning has been passed to the administration of archive.org, but no official statements or explanations have been published yet (only retweets on Twitter). The SQL dump obtained by researchers is more than 6 GB in size and, among other things, includes user password hashes in bcrypt format, password change times, email addresses, and usernames. The most recent entry in the database is dated September 28.
The relevance of the database was confirmed by well-known security researcher Scott Helme, whose password hash and change time from the leaked SQL dump matched the data from his password manager. Users can check for compromises of their accounts through the service haveibeenpwned.com, which has already added information from the leaked archive.org database. In general, the check on haveibeenpwned.com covers 14 billion passwords and includes information about breaches from 817 sites.
Sursa: opennet.ro
