United Nations hit by possible state-sponsored attack

At least 40 servers were compromised over three separate European offices, according to a leaked report

Hackers managed to infiltrate a slew of servers at three separate United Nation offices last year in what is reported as apparent espionage action. 

The extent of the hack, along with the identity of the perpetrators are unknown, and the attack itself has only just come to light thanks to a leaked document reported by The New Humanitarian

Advertisement - Article continues below

At least 40 servers at UN offices in Vienna, Geneva and the UN Office of the High Commissioner for Human rights - also located in Geneva - were compromised, according to the leaked document dated 20 September 2019. 

The UN suffered a "major meltdown", an unnamed UN official told TNH, and "Multiple workshops and assessments have been conducted to verify that the exploited vulnerabilities have been mitigated."

The cyber attack was so "sophisticated" that it was possibly the work of a state-backed actor, another official told the Associated Press

"It's as if someone were walking in the sand, and swept up their tracks with a broom afterward," the official said. "There's not even a trace of a cleanup."

The attack began in the middle of July last year and was first reported by an IT official working at the Geneva office on 30 August: "We are working under the assumption that the entire domain is compromised. The attacker doesn't show signs of activity so far, we assume they established their position and are dormant."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

It also included systems for the UN's human rights and human resources departments and breached some administrator accounts. The affected system included core infrastructure where user and management passwords, system controls and security firewalls were stored. Despite not being told what had happened, staff were asked to change their passwords.

Related Resource

How do vulnerabilities get into software?

90% of security incidents result from exploits against defects in software

Download now

"The attack resulted in a compromise of core infrastructure components," said UN spokesperson Stéphane Dujarric, according to TNH. "As the exact nature and scope of the incident could not be determined, [the UN offices in Geneva and Vienna] decided not to publicly disclose the breach."

The UN has diplomatic status and is therefore immune from the legal process, so there is no regulation enforcing it to disclose breaches of data. 

Featured Resources

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Remote working 2020: Advantages and challenges

Discover how to overcome remote working challenges

Download now

Keep your data available with snapshot technology

Synology’s solution to your data protection problem

Download now

After the lockdown - reinventing the way your business works

Your guide to ensuring business continuity, no matter the crisis

Download now
Advertisement

Recommended

Russia hacked Liam Fox's personal email to steal trade documents
phishing

Russia hacked Liam Fox's personal email to steal trade documents

4 Aug 2020
British teenager charged over Twitter hack
hacking

British teenager charged over Twitter hack

3 Aug 2020
Mid-year report says vulnerabilities up 22% in 2020
hacking

Mid-year report says vulnerabilities up 22% in 2020

30 Jul 2020
BlackRock banking Trojan targets Android apps
trojans

BlackRock banking Trojan targets Android apps

27 Jul 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How do you build a great customer experience?
Sponsored

How do you build a great customer experience?

20 Jul 2020
Labour Party donors caught up in Blackbaud data breach
data breaches

Labour Party donors caught up in Blackbaud data breach

31 Jul 2020