UNDP confirmed data theft after ransomware attack on Copenhagen IT systems

Organization
United Nations Development Programme (UNDP)
Exploit
Ransomware
Industry
International Development

The United Nations Development Programme said it received threat intelligence on March 27, 2024 indicating that a data-extortion actor had stolen information from local information technology infrastructure at UN City in Copenhagen, the campus that houses several UN agencies.

UNDP said the stolen material covered human resources and procurement records, including personally identifiable information on current and former employees and records relating to suppliers and contractors. The agency contained the affected server, opened an investigation into what exactly had been taken, notified the individuals and entities for which it had contact details, and alerted other UN bodies and partners.

The 8Base ransomware group listed UNDP on its leak site the same day the agency was tipped off, setting a publication deadline of April 3, 2024. In its posting the group claimed to hold accounting documents, personal data, employment contracts, confidentiality agreements, personnel files, certificates, invoices and receipts, along with what it described as a huge amount of confidential information. Reporters who checked afterward found the download link had expired.

UNDP stated that it does not engage with threat actors and that no ransom had been or would be paid. In its April 2024 statement the agency said it had no evidence of actual or attempted misuse of the stolen data, and it did not comment publicly on 8Base's specific claims about what had been taken.

Sources