The U.N. accidentally released passwords, internal documents, and other sensitive details when it failed to properly secure its accounts on Trello, a popular workplace project management website.
According to The Intercept, “[a]ffected data included credentials for a U.N. file server, the video conferencing system at the U.N.’s language school, and a web development environment for the U.N.’s Office for the Coordination of Humanitarian Affairs.” It was made available to anyone who had the links to the material as opposed to specific users granted access.
The security slips were first identified by Security researcher Kushagra Pathak back in August after he conducted Google searches, which led him to public Trello pages that also linked to Google documents and Jira pages. Jira is an “issue tracking app,” as noted by The Intercept.
Despite Pathak’s attempts to notify the U.N., the international governing body first took two weeks to respond and verify they would investigate his concerns. A little over a week later, they told him they were unable to locate the vulnerabilities and asked for more information on how he located the exposed information. “May we request you to provide the exact Google search criteria that was used?” they asked him.
Throughout this time, he continued to send them his findings on the publicly available information.
“In all, he reported 60 Trello boards, several Google Drive and Google Docs links that contained sensitive information, and sensitive information from a public U.N. account on Jira,” The Intercept reports.
The outlet also says they contacted the U.N. on September 12, and a day later, they started taking down the exposed information.
In an email statement to The Intercept, U.N. spokesperson Florencia Soto Nino-Martinez said :
“Some of the boards listed have communications materials which are not sensitive, while some have outdated information. However, we are reviewing all boards on the list to ensure that no passwords or credentials are shared through this medium.”
She also said:
“We take security very seriously and have reached out to all staff reminding them of the risks of using a third-party platform to share content and to take the necessary precautions to ensure no sensitive content is public.”
The Intercept noted “just some” of the information made available to the public:
A social media team promoting the U.N.’s “peace and security” efforts published credentials to access a U.N.