HomeSecurityUN investigates ransomware attack with data theft

UN investigates ransomware attack with data theft

The United Nations Development Programme (UNDP) is investigating a ransomware attack after breached its IT systems to steal human resources data.

See also: Over 40 countries to sign to stop paying ransoms to ransomware gangs

UN ransomware attack

UNDP, the UN's global development network, works in more than 170 countries and territories and relies on donations from UN Member States and private sector/multilateral organizations to help eradicate poverty and combat inequality and exclusion.

In a statement released on Tuesday, the organization revealed that attackers breached local IT infrastructure in the UN city of Copenhagen in late March.

" On March 27, the UN received an alert that a ransomware attack had stolen data that included certain human resources and information procurement ," the UN agency revealed

The UNDP is now investigating the nature and scope of the incident and assessing the impact of the attack on individuals whose information was stolen. It also notified and is now working with those affected by the breach, so they can protect their personal data from misuse.

While the UN agency has yet to link the attack to a specific group, the 8Base added a new UNDP entry to its data leak website on March 27.

The attackers say that the documents their handlers managed to exploit during the breach contain large amounts of sensitive information. The files temporarily leaked via an expired link reportedly include “a huge amount of confidential information,” including personal data, accounting data, certificates, employment contracts, confidentiality agreements, invoices, receipts, and more.

See also: Hive ransomware: 10 million reward for information on its members

The 8Base ransomware attack on the UN appeared in March 2022 and its activity skyrocketed in June 2023, after they began attacking companies across a wider range of industries and turned to double-crossing extortion.

UN investigates ransomware attack with data theft

The gang launched the data leak website in May 2023, with the extortion group claiming to be “honest and simple” pen testers, targeting “companies that have neglected the privacy and importance of their employees’ and customers’ data.”

So far, the ransomware group has listed over 350 victims of the attack on its website, in addition to the UN, announcing up to six victims at once on some days. 8Base uses a customized version of the Phobos, a malware that first appeared in 2019 and shares many code similarities with the Dharma ransomware.

The United Nations Environment Programme (UNEP) also revealed a data breach in January 2021, after more than 100,000 employee records containing personally identifiable information (PII) were exposed online.

United Nations networks in Geneva and Vienna were also breached in July 2019 through a SharePoint vulnerability, exposing personnel records, health insurance and commercial contract data in what a UN official described as a "major breach."

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Carolina Foods company fell victim to ransomware attack

What is the latest technology against ransomware attacks?

Artificial Intelligence (AI) and Machine Learning (ML) technology is one of the latest and most effective methods for combating ransomware attacks, such as the one at the UN. These technologies can identify and analyze ransomware behavior patterns, allowing attacks to be prevented before they occur. Endpoint Detection and Response (EDR) is also another important innovation. EDR is designed to detect, investigate, and respond to threats , providing protection against ransomware attacks, such as the one at the UN. Finally, browser isolation technology is another recent technology that can help protect against ransomware attacks. This technology isolates browser processes from the rest of the system, preventing the spread of ransomware.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS