Site icon BW Security World

UNDP Suffered Data Extortion Cyberattack

Upon learning of the breach, the UNDP  responded by initiating measures to both identify the source of the attack and contain its spread. Efforts were directed towards assessing the extent of the intrusion and determining the potential risks posed to individuals and entities associated with the compromised data

The United Nations Development Programme (UNDP) suffered a large scale data breach , alongside the IT systems of Copenhagen, Denmark. The attack, which occurred towards the end of March, saw data breaches affecting crucial areas such as human resources and procurement within the UN agency.

Upon learning of the breach, the UNDP  responded by initiating measures to both identify the source of the attack and contain its spread. Efforts were directed towards assessing the extent of the intrusion and determining the potential risks posed to individuals and entities associated with the compromised data.

In a statement addressing the incident, the UNDP emphasised its commitment to addressing the situation with urgency and transparency. The agency undertook comprehensive efforts to ascertain the nature and scope of the exposed data, reaching out to affected parties and engaging with relevant stakeholders, including partners within the UN system.

Despite the UNDP’s efforts to mitigate the impact of the cyberattack, the identity of the threat actor remains undisclosed. However, 8Base, a group specializing in ransomware attacks, claimed responsibility for the breach. In an update to their website in early April, 8Base listed the UNDP among its victims, alongside three other entities.

According to the group, a range of sensitive information, including personal data, certificates, and confidential documents, was compromised and uploaded to servers. Among the data exposed were invoices and other significant records, highlighting the severity of the breach and its potential implications for affected parties.

As the UNDP continues to navigate the aftermath of the cyberattack, its focus remains on bolstering cybersecurity measures and safeguarding the integrity of its systems. The incident serves as a stark reminder of the ever-present threat posed by cybercriminals and the critical importance of robust cybersecurity protocols in safeguarding sensitive data and maintaining organizational resilience.

Exit mobile version