What a ridiculous hack. I hope Karma pays a visit very soon. Or, better yet, turn the folks posting on reddit loose on the hacker. They are madder than mad.
"Update 10/10/24: Internet Archive founder Brewster Kahle shared an update on X last night, confirming the data breach ....."
The security breech that allowed access to 31 million user's data is one issue. The second issue is, as of tonight, the ongoing DDoS attack on the website. This has caused the website to go offline. According to bleepingcomputer.com, "the Internet Archive suffered a DDoS attack, which has now been claimed by the Black Me ta hack ti vist (spaces inserted intentionally) group, who says they will be conducting additional attacks."
Brewster Kahle stated that for now they are able to fend off the DDoS attack.
About the data breach, the bad guys now have our email addresses. Wow, who doesn't. And hashed (salted) encrypted passwords, using bcrypt. This means they do not have the password in plain text that would enable them to read it. To "decrypt" 31 million passwords, or just a few thousand, would take an enormous amount of time and computer resources. But, they may hope to luck up upon an account that used a lame simple password. And, they are hoping that the account uses the same password and email address for all, or many, websites, like online banking!
There are some accounts on the Internet Archives that contain personal information. If you have contributed information your account may be more detailed.
As of today, I think, maybe yesterday, all the account information for each user has been released by the hacker to the website HBIP (Have I Been Pwned). You can search their website to see if your email address appears.
There is speculation about why the hack occurred. The hacker made no mention of how the data would be used (abused). If you suddenly begin receiving an increase in spam email or any email that contains a link to a website then it may be a sign they have sold your email address to spammers and phishers. But, if you've spent more than 24 hours on the Internet, that has probably already been done.
If you are someone who uses the same username and password for all websites, or simple passwords that do not contain numbers, capital letters and symbols then you need to change your wicked ways. You need to change all your passwords and create a new email address that you use for website registrations, not personal correspondence. Also, take advantage of your browser generated passwords. However, BE SURE your computer, laptop or tablet is password protected, with a strong password.
I did read where some recommend changing your password to the Internet Archives. It certainly won't hurt.