Feeds

UN's lax security exposed by password-slurping hacktivists

Login details and email addresses dumped after raid

5 things you didn’t know about cloud backup

Hacktivist group TeaMp0isoN has hacked into the website of the United Nations Development Programme, making off with hundreds of email addresses, usernames and plain-text passwords that were later dumped onto Pastebin.

Individuals working for the UNDP, the Organisation for Economic Co-operation and Development, UNICEF, the World Health Organisation and other groups were exposed by the hack, which revealed lax password security at the agencies. Some of the accounts appeared to have a blank password and many more have easily guessable login credentials. And storing passwords in plain-text (rather than an encrypted form) is an even bigger mistake, of course.

TeaMp0isoN said that it carried out the attack as a protest against what it sees as corruption at the UN. In particular it is upset with the organisation's handling of the genocide in Rwanda, the break-up of Yugoslavia and the Palestinian-Israeli conflict, among other matters.

Security watchers were skeptical of the UN's attempt to downplay the significance of the hack.

Jason Hart, managing director of Cryptocard, commented: “The UN is seen as a symbol for security and trust for many millions of people around the world. Hacking their systems is TeaMp0isoN's way of making a big statement to the outside world.”

“The UN has said that the information exposed is old data, but if you look at the YouTube video released by the hackers on Monday it shows account details and usernames as well as personal email addresses. As we all know, passwords cross personal and professional lives, so these people could well be compromised at work and at home," Hart added.

TeaMp0isoN recently joined forces with Anonymous as part of Operation Robin Hood, which aims to defraud banks by making donations to charities and other worthwhile causes using stolen credit card details.

More security commentary on TeaMp0isoN's antics can be found in a blog post by Sophos here. ®

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.