Please ensure Javascript is enabled for purposes of website accessibility

West Bank Town Becomes ‘Big Prison’ as Israel Fences It In

2 days ago

Trump Says He’s Willing to Let Migrant Farm Laborers Stay in US

2 days ago

US Electric Vehicle Tax Breaks Will Expire on Sept. 30

2 days ago

Eyeing Arctic Dominance, Trump Bill Earmarks $8.6 Billion for US Coast Guard Icebreakers

2 days ago

Trump’s Sweeping Tax-Cut and Spending Bill Wins Congressional Approval

2 days ago

Americans Celebrate Their Independence With Record-Breaking Travel Numbers

3 days ago

US Supreme Court to Decide Legality of Transgender School Sports Bans

3 days ago

Nvidia Set to Become the World’s Most Valuable Company in History

3 days ago

Poll: 41% in US ‘Extremely Proud’ to Be American, Near Historic Low

3 days ago
Leaked Report Shows United Nations Suffered Hack
gvw_ap_news
By Associated Press
Published 5 years ago on
January 29, 2020

Share

GENEVA — Sophisticated hackers infiltrated U.N. offices in Geneva and Vienna last year in an apparent espionage operation, and their identity and the extent of the data they obtained is unknown.

“It’s as if someone were walking in the sand, and swept up their tracks with a broom afterward. There’s not even a trace of a clean-up.” a U.N. official 
An internal confidential document from the United Nations, leaked to The New Humanitarian and seen by T he Associated Press, says dozens of servers were compromised including at the U.N. human rights office, which collects sensitive data and has often been a lightning rod of criticism from autocratic governments for exposing rights abuses.
Asked about the report, one U.N. official told the AP that the hack appeared “sophisticated” and that the extent of the damage remained unclear, especially in terms of personal, secret or compromising information that may have been stolen. The official, who spoke only on condition of anonymity to speak freely about the episode, said systems have since been reinforced.
The skill level was so high it is possible a state-backed actor might have been behind it, the official said.
“It’s as if someone were walking in the sand, and swept up their tracks with a broom afterward,” the official said. “There’s not even a trace of a clean-up.”
The leaked Sept. 20 report says logs that would have betrayed the hackers’ activities inside the U.N. networks — what was accessed and what may have been siphoned out — were “cleared.” It also shows that among accounts known to have been accessed were those of domain administrators — who by default have master access to all user accounts in their purview.

The Intrusion Definitely Looks Like Espionage

“Sadly … still counting our casualties,” the report says.
Jake Williams, CEO of the cybersecurity firm Rendition Infosec and a former U.S. government hacker, said the fact that the hackers cleared the network logs indicates they were not top flight. The most skilled hackers — including U.S., Russian and Chinese agents — can cover their tracks by editing those logs instead of clearing them.
“The intrusion definitely looks like espionage,” said Williams, noting that the active directory component — where all users’ permissions are managed — from three different domains were compromised: those of United Nations offices in Geneva and Vienna and of the Office of the High Commissioner for Human Rights.
“This, coupled with the relatively small number of infected machines, is highly suggestive of espionage,” he said after viewing the report. “The attackers have a goal in mind and are deploying malware to machines that they believe serve some purpose for them.”
Any number of intelligence agencies from around the globe are likely interested in infiltrating the U.N., Williams said.
The hack was not severe at the U.N. human rights office, said its spokesman, Rupert Colville.
“We face daily attempts to get into our computer systems ,” Colville said. ” This time, they managed, but it did not get very far. Nothing confidential was compromised.”

Photo of Michelle Bachelet, United Nations High Commissioner for Human Rights
FILE – In this April 9, 2019, file photo Michelle Bachelet, United Nations High Commissioner for Human Rights, attends a press conference at the Cultural Center of Spain, in Mexico City. An internal confidential document from the United Nations, leaked to The New Humanitarian and seen by The Associated Press, says that dozens of servers were “compromised” at offices in Geneva and Vienna.Those include the U.N. human rights office, which has often been a lightning rod of criticism from autocratic governments for its calling-out of rights abuses. (AP Photo/Marco Ugarte, File)

42 Servers Were ‘Compromised’ and Another 25 Were Deemed ‘Suspicious’

U.N. spokesman Stephane Dujarric said the attack “resulted in a compromise of core infrastructure components” and was “determined to be serious.” The earliest detected activity related to the intrusion occurred in July and it was detected in August, he said in response to emailed questions.

“The damage related to this specific attack has been contained, and additional mitigation measures implemented. Nevertheless the threat of future attacks continues, and the United Nations Secretariat detects and responds to multiple attacks of various level of sophistication on a daily basis.” — U.N. spokesman Stephane Dujarric
He said the world body does not have enough information to determine who might have been behind the incursion, but added “the methods and tools used in the attack indicate a high level of resource, capability and determination.
“The damage related to this specific attack has been contained, and additional mitigation measures implemented,” Dujarric wrote. “Nevertheless the threat of future attacks continues, and the United Nations Secretariat detects and responds to multiple attacks of various level of sophistication on a daily basis.”
The internal document from the U.N. Office of Information and Technology said 42 servers were “compromised” and another 25 were deemed “suspicious,” nearly all at the sprawling Geneva and Vienna offices. Three of the “compromised” servers belonged to Human Rights agency, which is located across town from the main U.N. office in Geneva, and two were used by the U.N. Economic Commission for Europe.
The report says a flaw in Microsoft’s SharePoint software was exploited by the hackers to infiltrate the networks but that the type of malware used was not known, nor had technicians identified the command and control servers on the internet used to exfiltrate information. Nor was it known what mechanism was used by the hackers to maintain their presence on the infiltrated networks.

Hack Comes Amid Rising Concerns About Computer or Mobile Phone Vulnerabilities

Security researcher Matt Suiche, a French entrepreneur based in Dubai who founded the cybersecurity firm Comae Technologies, reviewed the report and said it appeared entry was gained through an anti-corruption tracker at the U.N. Office of Drugs and Crime.
The report mentions a range of IP addresses in Romania that may have been used to stage the infiltration, and Williams said one is reported to have some neighbors with a history of hosting malware.
Technicians at the United Nations office in Geneva, the world body’s European hub, on at least two occasions worked through weekends in recent months to isolate the local U.N. data center from the internet, re-write passwords and ensure the systems were clean. Twenty machines had to be rebuilt, the report says.
The hack comes amid rising concerns about computer or mobile phone vulnerabilities, both for large organizations like governments and the U.N. as well as for individuals and businesses.
Last week, U.N. human rights experts asked the U.S. government to investigate a suspected Saudi hack that may have siphoned data from the personal smartphone of Jeff Bezos, the Amazon founder and owner of The Washington Post, in 2018. On Tuesday, T he New York Times’s bureau chief in Beirut, Ben Hubbard, said technology researchers suspected an attempted intrusion into his phone around the same time.

Potentially Affected Are Staff in the Office of the Special Envoy for Syria

The United Nations, and its human rights office, is particularly sensitive, and could be a tempting target. The U.N. High Commissioner for Human Rights, Michelle Bachelet, and her predecessors have called out, denounced and criticized alleged war crimes, crimes against humanity and less severe rights violations and abuses in places as diverse as Syria and Saudi Arabia.

“There’s a lot of our data that could have been hacked, and we don’t know what that data could be.” — Ian Richards, president of the Staff Council at the United Nations
Dozens of independent human rights experts who work with the U.N. human rights office have greater leeway — and fewer political and financial ties to the governments that fund the United Nations and make up its membership — to denounce alleged rights abuses.
Ian Richards, president of the Staff Council at the United Nations, expressed concern about the safety of U.N. networks.
“There’s a lot of our data that could have been hacked, and we don’t know what that data could be,” said Richards, whose group advocates for the welfare of employees of the world body.
Potentially affected, for example, are staff in the office of the special envoy for Syria carrying out sensitive investigations and human rights staffers interviewing witnesses.
“How much should U.N. staff trust the information infrastructure the U.N. is providing them?” Richards asked. “Or should they start putting their information elsewhere?”
[activecampaign form=29]

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

How Trump’s ‘Big, Beautiful Bill’ Will Make China Great Again

DON'T MISS

What’s Caitlin Clark Worth to the WNBA? A Lot More Than Her $78,066 Salary.

DON'T MISS

Trump to Sign Tax-Cut and Spending Bill in July 4 Ceremony

DON'T MISS

Madre Fire Spurs Evacuations Across 3 Counties, Grows to More Than 70,000 Acres

DON'T MISS

Clovis, Sanger, Madera, and Bass Lake Will Light the Sky With Fireworks Shows Tonight

DON'T MISS

Oil Dips Ahead of Expected OPEC+ Output Increase

DON'T MISS

613 Killed at Gaza Aid Distribution Sites, Near Humanitarian Covoys, Says UN

DON'T MISS

Fresno County Authorities Investigating Suspicious Death of Transient Man

DON'T MISS

West Bank Town Becomes ‘Big Prison’ as Israel Fences It In

DON'T MISS

Israeli Military Kills 20 in Gaza as Trump Awaits Hamas Reply to Truce Proposal

UP NEXT

West Bank Town Becomes ‘Big Prison’ as Israel Fences It In

UP NEXT

Israeli Military Kills 20 in Gaza as Trump Awaits Hamas Reply to Truce Proposal

UP NEXT

Russia Pounds Kyiv With Largest Drone Attack, Hours After Trump-Putin Call

UP NEXT

Markets’ 90-Day Tariff Pause Rollercoaster Nears an Uncertain End

UP NEXT

Fresno Crash Involving Unlicensed Teen Driver Sends Woman to Hospital

UP NEXT

Eyeing Arctic Dominance, Trump Bill Earmarks $8.6 Billion for US Coast Guard Icebreakers

UP NEXT

Colombia President Recalls Ambassador to US

UP NEXT

US-Backed 60-Day Gaza Ceasefire Envisions Gradual Return of Hostages, Official Says

UP NEXT

Americans Celebrate Their Independence With Record-Breaking Travel Numbers

UP NEXT

US Paves Way to Resume Ethane Exports to China Amid Trade Truce

Madre Fire Spurs Evacuations Across 3 Counties, Grows to More Than 70,000 Acres

1 day ago

Clovis, Sanger, Madera, and Bass Lake Will Light the Sky With Fireworks Shows Tonight

2 days ago

Oil Dips Ahead of Expected OPEC+ Output Increase

2 days ago

613 Killed at Gaza Aid Distribution Sites, Near Humanitarian Covoys, Says UN

2 days ago

Fresno County Authorities Investigating Suspicious Death of Transient Man

2 days ago

West Bank Town Becomes ‘Big Prison’ as Israel Fences It In

2 days ago

Israeli Military Kills 20 in Gaza as Trump Awaits Hamas Reply to Truce Proposal

2 days ago

Valley Crime Stoppers’ Most Wanted Person of the Day: Rachelle Maria Blanco

2 days ago

Russia Pounds Kyiv With Largest Drone Attack, Hours After Trump-Putin Call

2 days ago

Boxer Chavez Jr Expected to Be Deported to Mexico to Serve Sentence, Mexican President Says

2 days ago

How Trump’s ‘Big, Beautiful Bill’ Will Make China Great Again

Can you hear it — that loud roar coming from the East? It’s the sound of 1.4 billion Chinese laughing at us. Thomas L. Friedman The New Yo...

15 hours ago

Solar Farm in Riesel, Texas
15 hours ago

How Trump’s ‘Big, Beautiful Bill’ Will Make China Great Again

Caitlin Clark Signs T-Shirt
15 hours ago

What’s Caitlin Clark Worth to the WNBA? A Lot More Than Her $78,066 Salary.

President Donald Trump speaks during a press conference in the Roosevelt Room at the White House in Washington, D.C., U.S., May 12, 2025. (Reuters File)
1 day ago

Trump to Sign Tax-Cut and Spending Bill in July 4 Ceremony

The Madre Fire burning near New Cuyama has scorched 70,801 acres as of Friday, July 4, 2025, afternoon, making it California’s largest wildfire of the year, with only 10% containment and multiple evacuation zones in place. (CalFire)
1 day ago

Madre Fire Spurs Evacuations Across 3 Counties, Grows to More Than 70,000 Acres

2 days ago

Clovis, Sanger, Madera, and Bass Lake Will Light the Sky With Fireworks Shows Tonight

A pumpjack operates at the Vermilion Energy site in Trigueres, France, June 14, 2024. (Reuters File)
2 days ago

Oil Dips Ahead of Expected OPEC+ Output Increase

Palestinians gather to collect what remains of relief supplies from the distribution center of the U.S.-backed Gaza Humanitarian Foundation, in Rafah, in the southern Gaza Strip, June 5, 2025. (Reuters File)
2 days ago

613 Killed at Gaza Aid Distribution Sites, Near Humanitarian Covoys, Says UN

Billy Wayne Sinisgalli, a 54-year-old transient known locally as Wayne, was found dead along a rural Fresno road Wednesday in what authorities are investigating as a suspicious death. (Fresno County SO)
2 days ago

Fresno County Authorities Investigating Suspicious Death of Transient Man

Help continue the work that gets you the news that matters most.

Search

Send this to a friend