In April 2021, the United Nations experienced a cyberattack “targeting users within the UN network
to further long-term intelligence gathering” (Center for Strategic & International Studies, 1),
resulting in the theft of private and sensitive information. The attacker was able to gain access to
the UN’s project management software through a compromised user ID and password found on the
dark web. According to Turton and Mehrotra in a Time e-zine article, the attacker was found to have
had access from April 5th through August 7, 2021. The attack was labeled as cyber espionage and
while the U.N. stated that it was limited to intelligence gathering via screenshots, an outside security
company working with the U.N. found proof that data had been stolen. The hackers were able to
map the U.N. computer network, making it more vulnerable to future attacks (2). The event
damaged the U.N.’s reputation as an agency with impeccable security measures and has made it a
more attractive target.
To stop the attack, the U.N.’s information security team performed an audit of active accounts and