Security

Internet Archive exposed again – this time through Zendesk

Org turns its woes into a fundraising opportunity


Despite the Internet Archive's assurances that it's back on its feet after a recent infosec incident, the org still appears to be in trouble after parties unknown claimed to hold access tokens to its Zendesk implementation and to have used them to send a mass email blast.

The claim was made on Sunday in the form of an email sent to those who have tried to interact with the Archive (IA) and had their requests routed to Zendesk – the SaaSy customer service platform.

The Register received the email in response to our most recent request for comment on the Archive's woes.

The mail opens: "It's dispiriting to see that even after being made aware of the breach 2 weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," before claiming the mail was made possible by the presence of a Zendesk token in that trove.

"As demonstrated by this message, this includes a Zendesk token with perms to access 800K+ support tickets sent to info@archive.org since 2018," the email states.

"Whether you were trying to ask a general question or requesting the removal of your site from the Wayback Machine – your data is now in the hands of some random guy. If not me, it'd be someone else," the unidentified e-mailer wrote, before finishing with "Here's hoping that they'll get their shit together now."

It's unclear if the author is the same entity who recently defaced the Archive's website and called out the org for lax infosec.

Posts to various social networks indicate The Register is far from alone in having received the mail.

The org's social feeds and blogs are silent on the matter at the time of writing.

But the Archive did manage to send at least one legitimate email last week – in which it asked for donations to help it work through its infosec issues.

"We apologize for the impact this caused on you, our valued users," that email read. "The support of our community is deeply appreciated, and your generosity and assistance can help us during this time. Please consider donating to support continued access to knowledge for all who seek it. We understand if you cannot contribute, but any assistance is greatly appreciated."

Anyone else feel like this might not be quite the moment to entrust the Internet Archive with credit card details? ®

Send us news
9 Comments

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

Release the Kraken!

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Merde! Macron's bodyguards reveal his location by sharing Strava data

It's not just the French president, Biden and Putin also reportedly trackable

Brazen crims selling stolen credit cards on Meta's Threads

The platform 'continues to take action' against illegal posts, we're told

AWS Cloud Development Kit flaw exposed accounts to full takeover

Remember Bucket Monopoly? Yeah, it gets worse