Report: UN did not tell the public nor its general staff about a hacking attack into its IT systems from last July, despite staff records being compromised
and then tried to cover it up Associated Press : Leaked report shows United Nations suffered hack Lindsey O'Donnell / Threatpost : U.N. Hack Stemmed From Microsoft SharePoint Flaw Igor Bonifacic / Engadget : UN confirms it suffered a ‘serious’ hack, but didn't inform employees Humza Aamir / TechSpot : Report reveals hackers infiltrated UN servers in Geneva and Vienna last year Zeljka Zorz / Help Net Security : UN hacked: Attackers got in via SharePoint vulnerability Pierluigi Paganini / Security Affairs : Leaked confidential report states United Nations has been hacked Phil Muncaster / infosecurity-magazine.com : Human Rights Fears as UN Admits Serious Breach Charlesarthur / The Overspill : Start Up No.1233: Facebook pivots off video, the dogs of Trump's campaign, the trouble with the Fold … Joel Khalili / TechRadar.com : UN ‘covered up’ serious data breach affecting thousands of workers Jamey Keaton / Associated Press : In ‘Sophisticated’ Incident, Dozens of United Nations Servers Hacked Tweets: Catalin Cimpanu / @campuscodi : The UN got hacked and they tried to keep it quiet https://www.thenewhumanitarian.org/ ... https://twitter.com/... Lukasz Olejnik / @lukolejnik : Systems of United Nations office in Geneva hacked last year. Lots of significant data could be affected. International orgs are not bound by the usual cybersecurity and privacy standards, nor transparency. Diplomatic immunity sometimes insufficient. https://www.thenewhumanitarian.org/ ... Kevin Beaumont / @gossithedog : SharePoint vulnerability CVE-2019-0604 from a year ago has been used to hack the UN. Three different UN agencies got owned, about 20 domain admin accounts accessed and implants on 40 servers. They didn't disclose. https://www.thenewhumanitarian.org/ ... Chris Vickery / @vickerysec : In Sept. 2017 I received a phone call from a high level individual within AWS Security during which I was criticized for reporting an exposed UN database to law enforcement instead of just letting the private company work it out. And now this: https://www.thenewhumanitarian.org/ ... @newhumanitarian : Long a target of spies, the @UN is subjected to highly targeted and sophisticated cyber attacks. This one got through its defences. https://www.thenewhumanitarian.org/ ... Mark Anderson / @markc_anderson : The UN did not publicly disclose a major hacking attack that compromised about 40 of its European servers. An estimated 400 gigabytes of data was downloaded from the servers, which hold a range of data, including personal information about staff. https://www.thenewhumanitarian.org/ ... Eva / @evacide : “Under diplomatic immunity, the UN is not obliged to divulge what was obtained by the hackers or notify those affected.” You're not obliged, but it sure is the right thing to do, unlike covering it up. https://twitter.com/... Patrick Vinck / @developmentdata : This is not a surprise. These were UN HQ IT systems. Now imagine the level of security of country offices who handle large amount of sensitive data, including biometrics. Time to apply data minimization and other ‘do-no-harm-with-data’ principles https://www.thenewhumanitarian.org/ ... Frances Harrison / @francesharris0n : What about victims and witnesses who shared testimony with .@UNHumanRights ? And what about UN ignoring gdpr norms? https://twitter.com/... Somini Sengupta / @sominisengupta : The UN's human rights office got hacked. We know that because of this scoop. https://twitter.com/... @newhumanitarian : The UN doesn't have to report a major data breach to anyone. It didn't. https://www.thenewhumanitarian.org/ ... @newhumanitarian : All over Europe, governments, corporations and non-profits have to report major hacks involving personal information. But not the UN. https://www.thenewhumanitarian.org/ ... @newhumanitarian : Two months after the attack began, a UN report on the breach contained a section titled “Still counting our casualties.” The attackers are unknown. https://www.thenewhumanitarian.org/ ... @dmsouthasia : *Hackers hit dozens of UN servers starting in July 2019. *Staff not told full extent of the breach. *Simple patch could have averted the attack. *UN officials warned of major vulnerabilities years ago. https://www.thenewhumanitarian.org/ ... Emma Beals / @ejbeals : The UN suffered a pretty big hack last year that is just now being revealed by the @newhumanitarian. Hack included the highly sensitive OHCHR office: https://www.thenewhumanitarian.org/ ...
Context & Ripple Effects
The UN joins a familiar club of breached institutions that disclosed late or not at all: Deloitte confirmed its own breach only after reporters asked, then downplayed the scope, and the FBI sat for over a year on knowledge that Fancy Bear was targeting hundreds of officials while warning only a few of them. What makes this report different is that the concealment came from an organization with no regulator above it to force disclosure.
The attack itself was unremarkable — roughly 40 servers in Geneva and Vienna breached via a known Microsoft SharePoint flaw, an estimated 400GB exfiltrated including staff personal records — which is precisely why the silence matters more than the intrusion. And it was not a one-off: a year and a half later hackers were inside the UN's Umoja project-management system for four months in the Resecurity-reported Umoja breach.
First-order effects
- UN staff learned their personnel records were among the estimated 400GB stolen only through a leaked internal report, not from their employer — the affected population was the last to know.
- Every organization still running the vulnerable on-premises SharePoint version now has proof that CVE-2019-0604 exploitation is not theoretical, putting immediate pressure on their patching cycles.
Second-order effects
- Member states and donors funding UN operations have grounds to question the organization's internal IT oversight, since the same body that audits others could not surface its own compromise.
- Microsoft faces renewed scrutiny of how widely exploited legacy SharePoint flaws are left unpatched across large institutional fleets, since the UN ran exposed servers months after the vulnerability was public.
Third-order effects
- International organizations sit outside the breach-notification regimes that bind companies in the US and EU, and this case plus the later Umoja intrusion suggest that without external reporting requirements, concealment is the default response.
- If leaks remain the only reliable disclosure channel for intergovernmental bodies, attackers gain a structural advantage: they can hold stolen staff data indefinitely without any clock forcing remediation or victim warning.
The trend: Breach disclosure at intergovernmental organizations is converging on a leak-driven model — incidents surface through journalists rather than notifications — leaving staff data exposed longer than in regulated private-sector equivalents.