UNICEF leaks personal data of 8,000 users

The security leak was quickly and proactively remedied and it's confident that it won't face a GDPR probe

UNICEF

The United Nations' children's agency UNICEF has leaked thousands of individuals' personal data through its online learning portal Agora.

An email was mistakenly sent on 26 August to 20,000 Agora users containing the private data belonging to 8,253 people who enrolled on the platform's immunisation courses.

Agora offers courses on child rights, humanitarian action, data, research and is used by UNICEF staff and members of the public.

"This was an inadvertent data leak caused by an error when an internal user ran a report," said Najwa Mekki, media chief at UNICEF in an email to Devex.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"The personal information accidentally leaked may include the names, email addresses, duty stations, gender, organization, name of supervisor and contract type of individuals who had enrolled in one of these courses, to the extent that these details were included in their Agora user's profile."

UNICEF became aware fi the incident a day after the email was sent and remedied the situation to "prevent such an incident from reoccurring".

Agora users were sent an email explaining the situation which then asked them to delete the spreadsheet full of data they may have received from their inboxes and their recycle bins too. The email also included an apology from UNICEF.

"Cybercriminals continue to build their database of account details and credentials," said Lisa Baergen, director at NuData Security.

"I continue to advise users to change their passwords immediately after being informed of a breach while not clicking on any links in unexpected emails, and to use unique passwords for each account they create."

Whether UNICEF will be subject to a GDPR investigation is undetermined as of yet, with some experts thinking that UNICEF may avoid one as it's a United Nations (UN) organisation.

Advertisement - Article continues below

Clare Sullivan, managing director of CyberSMART told Devex that UNICEF will probably be exempt from a GDPR probe as a UN body but it's something that still hasn't been tested in court.

Mekki, however, took a more absolute approach when addressing the question and said: "UN entities are not subject to GDPR" and that UNICEF did not report the case to authorities.

"The fact that UN organisations are not subject to GDPR should not mean that data protection practices should fall off the radar," said Javvad Malik, security awareness advocate at KnowBe4.

"All companies - and specifically intergovernmental organisations - should look to improve their cyber security posture, ensuring all staff are aware of their responsibilities."

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020