Threat actors accessed the organizations proprietary project management software, Umoja, in April, accessing the network and stealing info that can be used in further attacks. Attack highlights why simply using a username/password combination to secure entry into a system on an organization’s larger network is so dangerous, one security expert says. The user of the account apparently had not enabled two-factor authentication (2FA), allowing attackers to use credentials to access the software and move deeper into the network from there. Attackers were active on the UN network for at least four months.”]
Source: https://threatpost.com/data-theft-united-nations/169357/