What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The incident targeted the United Nations Development Programme’s local IT infrastructure in Copenhagen; it was not reported as a breach of the entire United Nations system. UNDP confirmed that human-resources and procurement information was stolen, while further sensitive data categories were reported in notifications reviewed by CyberScoop.

What happened, and when?

UNDP said it received a threat-intelligence notification on March 27, 2024, that a data-extortion actor had stolen information. The attack targeted local IT infrastructure at UN City in Copenhagen. In a statement dated April 16, UNDP said it had identified a potential source of the incident, contained the affected server and was assessing the data and people involved.

CyberScoop reported that attackers accessed multiple servers. UNDP’s public statement did not provide a complete inventory of the stolen material or describe the full extent of the affected systems.

What information may have been stolen?

UNDP confirmed that the stolen information included certain human-resources and procurement data. CyberScoop, citing notifications sent to affected people, reported that the exposed information may also have included:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Dates of birth and Social Security numbers
  • Bank-account information and passport details
  • Information about family members
  • Contractor information

Those additional categories come from the notifications reviewed by CyberScoop, not from a complete public inventory issued by UNDP. The available accounts do not establish that every listed category applied to every person affected.

Was the attack linked to 8Base?

CyberScoop reported that the 8Base ransomware operation claimed the attack on its extortion site on March 27 and said the data was published on April 3. The link to the material had expired by the time of CyberScoop’s report. INCIBE-CERT also recorded the 8Base claim.

UNDP did not name the attackers. The group’s claim is therefore not confirmed attribution: the public information supports saying that 8Base claimed responsibility, not that UNDP or an independent investigation verified the group carried out the attack.

How much data was taken?

CyberScoop described the stolen material as a “large volume of data,” but the cited public accounts provide no verified byte count or number of records or people affected. The phrase is qualitative; it does not establish a measurable size.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did UNDP do after the attack?

In its April 16 statement, UNDP said it contained the affected server and assessed what information had been exposed and who might be affected. It also said it communicated with affected people and informed other stakeholders across the UN system.

What remains unknown?

  • The exact number of affected people, records or bytes has not been published in the cited accounts.
  • The available information does not establish the initial-access method or a specific vulnerability used in the attack.
  • No confirmed ransom demand is reported in those accounts.
  • UNDP has not publicly confirmed 8Base as the attacker.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.