You are here: Home » Technology » News
Business Standard

United Nations' computer networks breached by hackers earlier this year

The hackers' method for gaining access to the UN network appears to be unsophisticated: They likely got in using the stolen username and password of a UN employee purchased off the dark web

United Nations | Hackers | Hacking

William Turton & Kartikay Mehrotra | Bloomberg 

The UN and its agencies have been targeted by hackers before.
The UN and its agencies have been targeted by hackers before.

breached the United Nations’ computer networks earlier this year and made off with a trove of data that could be used to target agencies within the intergovernmental organization.

The hackers’ method for gaining access to the UN network appears to be unsophisticated: They likely got in using the stolen username and password of a UN employee purchased off the

“We can confirm that unknown attackers were able to breach parts of the infrastructure in April of 2021,” Stéphane Dujarric, spokesman for the UN Secretary-General, said in a statement on Thursday. “The is frequently targeted by cyberattacks, including sustained campaigns. We can also confirm that further attacks have been detected and are being responded to, that are linked to the earlier breach.”

The credentials belonged to an account on the UN’s proprietary project management software, called Umoja. From there, the were able to gain deeper access to the UN’s network, according to cybersecurity firm Resecurity, which discovered the breach. The earliest known date the obtained access to the UN’s systems was April 5, and they were still active on the network as of Aug. 7.

“Organizations like the UN are a high-value target for cyber-espionage activity,” Resecurity Chief Executive Officer Gene Yoo said. “The actor conducted the intrusion with the goal of compromising large numbers of users within the UN network for further long-term intelligence gathering.”

The attack marks another high-profile intrusion in a year when hackers have grown more brazen. JBS SA, the world’s largest meat producer, was hit by a cyberattack this year that forced the shutdown of U.S. plants. Colonial Pipeline Co., operator of the biggest U.S. gasoline pipeline, also was compromised by a so-called ransomware attack. Unlike those hacks, whoever breached the UN didn’t damage any of its systems, but instead collected information about the UN’s computer networks.

According to Resecurity, company officials informed the UN of its latest breach earlier this year and worked with organization’s security team to identify the scope of the attack. The UN’s Dujarric said the international organization had already detected the attack.

UN officials informed Resecurity that the hack was limited to reconnaissance, and that the hackers had only taken screenshots while inside the network, according to Resecurity. When Resecurity’s Yoo provided proof to the UN of stolen data, the UN stopped corresponding with the company, he said.

The Umoja account used by the hackers wasn’t enabled with two-factor authentication, a basic security feature. According to an announcement on Umoja’s website in July, the system migrated to Microsoft Corp.’s Azure, which provides multifactor authentication. That move “reduces the risk of cybersecurity breaches,” an announcement on Umoja’s site read.

The UN and its agencies have been targeted by hackers before. In 2018, Dutch and British law enforcement foiled a Russian cyberattack against the Organisation for the Prohibition of Chemical Weapons as it probed the use of a deadly nerve agent on British soil. Then, in August 2019, the UN’s “core infrastructure” was compromised in a cyberattack that targeted a known vulnerability in Microsoft’s SharePoint platform, according to a report by Forbes. The breach wasn’t publicly disclosed until it was reported by the New Humanitarian news organization.

In the latest breach, hackers sought to map out more information about how the UN’s computer networks are built, and to compromise the accounts of 53 UN accounts, Resecurity said. Bloomberg News wasn’t able to identify the hackers or their purpose in breaching the UN.

Bloomberg News did review ads where users across at least three marketplaces were selling these same credentials as recently as July 5.

The reconnaissance carried out by the hackers may enable them to conduct future hacks or to sell the information to other groups that may seek to breach the UN.

“Traditionally, organizations like the have been targeted by nation state actors, but as cybercriminals are finding ways to more effectively monetize stolen data and as access to these organizations is more frequently available for sale by initial access brokers, we expect to see them increasingly targeted and infiltrated by cybercriminals,” said Allan Liska, a senior threat analyst at Recorded Future. Liska said he had seen the username and password for UN employees for sale on the

The credentials have been offered by multiple Russian-speaking cybercriminals, according to Mark Arena, chief executive officer of security-intelligence firm Intel 471. The UN credentials were being sold as part of a patch of dozens of usernames and passwords to various organizations for just $1,000.

“Since the start of 2021 we’ve seen multiple financially motivated cybercriminals selling access to the Umoja system run by the United Nations,” Arena said. “These actors were selling a broad range of compromised credentials from a multitude of organizations at the same time. In a number of previous occasions, we’ve seen compromised credentials being sold to other cybercriminals, who have undertaken follow up intrusion activity within these organizations.”

Dear Reader,

Business Standard has always strived hard to provide up-to-date information and commentary on developments that are of interest to you and have wider political and economic implications for the country and the world. Your encouragement and constant feedback on how to improve our offering have only made our resolve and commitment to these ideals stronger. Even during these difficult times arising out of Covid-19, we continue to remain committed to keeping you informed and updated with credible news, authoritative views and incisive commentary on topical issues of relevance.
We, however, have a request.

As we battle the economic impact of the pandemic, we need your support even more, so that we can continue to offer you more quality content. Our subscription model has seen an encouraging response from many of you, who have subscribed to our online content. More subscription to our online content can only help us achieve the goals of offering you even better and more relevant content. We believe in free, fair and credible journalism. Your support through more subscriptions can help us practise the journalism to which we are committed.

Support quality journalism and subscribe to Business Standard.

Digital Editor

First Published: Fri, September 10 2021. 23:19 IST