Security News > 2020 > January > How to avoid the mistakes made in the UN data breach
Targeting UN networks in Geneva and Vienna, the attacker was able to compromise accounts and data at dozens of servers, prompting one senior UN IT official to call it a "Major meltdown," the New Humanitarian said.
"These things...attempts to attack the UN IT infrastructure happen often. The attribution of any IT attack is remains very fuzzy and uncertain. So, we are not able to pinpoint to any specific potential attacker, but it was, from all accounts, a well‑resourced attack."
Though the hacker hit only development servers and may not have compromised sensitive information, the attack points to two errors or missteps made by the UN. First, the organization failed to properly patch its systems and servers ahead of time.
While the UN grapples with the revelation of this attack, the matter serves as a warning to other organizations on how to prevent and deal with data breaches.
TechRepublic: How was the hacker able to gain access to UN servers? I know it was through a flaw in SharePoint, but can you explain exactly how the flaw was exploited?
News URL
Related news
- ADT confirms data breach after customer info leaked on hacking forum (source)
- CSC ServiceWorks discloses data breach after 2023 cyberattack (source)
- How to Prevent Your First AI Data Breach (source)
- Toyota confirms third-party data breach impacting customers (source)
- National Public Data Breach: Only 134 Million Unique Emails Leaked and Company Acknowledges Incident (source)
- CannonDesign confirms Avos Locker ransomware data breach (source)
- Patelco notifies 726,000 customers of ransomware data breach (source)
- Nearly 1/3 of Companies Suffered a SaaS Data Breach in Last Year (source)
- Park’N Fly notifies 1 million customers of data breach (source)
- GDPR Data Breach Notification Letter (Free Download) (source)