Categories: Data Breach

UN Data Breach Exposes Over 100,000 UN Employees’ Details

UN Data Breach Exposes Over 100,000 UN Employees’ Details

Sakura Samurai discovered an endpoint that exposed GitHub credentials on a United Nations Environment Program (UNEP) subdomain, which allowed them to access more than 100,000 UN employees’ records.

A group of cybersecurity researchers from Sakura Samurai accessed around 100,000 personal records and login credentials of United Nations’ (UN) employees that were exposed in a data breach. Sakura Samurai is an ethical hacking and security research group appointed to report security flaws to the UN under its vulnerability disclosure program and a Hall of Fame.

During the vulnerability discovery, the research team found an open subdomain for the UN body, the International Labor Organization (ilo.org), which gave them access to Git credentials. The researchers then exfiltrated the Git credentials tool, git-dumper, to take over a legacy MySQL database and a survey management platform. Sakura Samurai group also discovered an exposed subdomain of the UN Environment Program (UNEP), which was also exposing Git credentials.

Also Read: Data Centre Regulations Singapore: Does It Help To Progress?

Exposed Personal Data

According to researcher John Jackson, a massive amount of Personally Identifiable Information (PII) was exposed, including:

Two documents containing more than 102,000 travel records, including employee IDs, numbers, names, employee groups, travel justification, start and end dates, length of stay, approval status, and destinations.

Two documents that contain more than 7,000 records related to HR Nationality Demographics, including employee name, ID numbers, person’s nationality, Gender, employee pay grade, organization work unit Identification number and unit text tags.

One document of Generalized Employee Records (contained more than 1,000 records)

Project and Funding Source Records (more than 4,000 records)

Evaluation Reports (contained details of 283 projects)

Data Breach Impact

The Sakura Samurai team claimed they were able to download a lot of private password-protected GitHub projects and found multiple sets of database and application credentials for the UNEP production environment. In total, they found seven additional credential-pairs, which could have resulted in unauthorized access to multiple databases.

Also Read: Website Ownership Laws: Your Rights And What These Protect

“We decided to stop and report this vulnerability once we were able to access PII that was exposed via Database backups that were in the private projects,” Sakura Samurai said.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

1 month ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago