CSIDB logo
Incident

United Nations

Incident posture

Attack window
Feb 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-27 00:11

Linked entities

Victim
United Nations
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker collective compromised a United Nations-affiliated platform supporting global internet policy discussions, exfiltrating data from over 3,200 unique user accounts. The breach exposed real names, usernames, email addresses, and encrypted passwords, with impacted accounts linked to government entities and spanning 537 distinct email providers. Attackers publicly disclosed the stolen credentials through online platforms, targeting an interactive forum designed for multi-stakeholder collaboration on internet governance issues. The organization's site facilitated dialogue among stakeholders under a UN mandate following the World Summit on the Information Society.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 20, 2014, the hacker collective @deletesec publicly announced a breach of the United Nations Internet Governance Forum (IGF) website, resulting in the leak of 3,215 user accounts. The compromised data included real names, usernames, email addresses, and encrypted passwords of individuals associated with the forum. The IGF website, registered to Chengetai Masango—the Programme and Technology Manager at the United Nations Secretariat for the IGF—served as a collaborative platform for multi-stakeholder policy discussions related to internet governance. Its primary function was to support the UN Secretary-General in facilitating dialogue mandated by the World Summit on the Information Society (WSIS). Attackers disclosed the breach via Twitter and published the stolen data on defuse.ca, exposing participants who used the platform to exchange views on global internet policy matters.

The leaked dataset contained 3,200 unique non-duplicate accounts spanning 537 distinct email providers, indicating broad international participation. Among the affected accounts were email addresses linked to government organizations, though specific agencies or nations were not detailed in the disclosure. The breach compromised credentials of stakeholders engaged in shaping internet governance policies through the UN-affiliated forum. No information regarding the exploitation methods, timeline of unauthorized access, or containment measures taken by the IGF or UN was disclosed in the announcement. The incident exposed sensitive user information but did not reveal whether password decryption attempts occurred or if secondary attacks resulted from the leak.

Sources

Sources available to members: 1 source.

CSIDB