The Internet Archive experienced three security breaches in October 2024 due to exploited unrotated Zendesk API tokens. The first breach occurred on October 9, with a data breach and DDoS attack from a pro-Palestinian group affecting 31 million users. A second breach in mid-October saw additional unrotated access tokens exploited. The third and latest breach arose from the same issues, causing additional damage. The breaches highlight the Internet Archive’s lack of proper token management and its susceptibility to repeat attacks.

Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms
Google-owned Mandiant on Friday said it identified an “expansion in threat activity” that uses tradecraft consistent with extortion-themed attacks orchestrated by a financially motivated hacking


