Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› United Nations Breach 2021: How Exposed Git Credentials…
Breach analysis Incident: 4 Jan 2021

United Nations Breach 2021: How Exposed Git Credentials Opened 100,000 UNEP Staff Records

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 9 min read
On this page

In January 2021, the ethical hacking group Sakura Samurai showed how far a single leaked credential can reach inside a large organisation. Working through the United Nations vulnerability disclosure programme, the researchers found web servers belonging to the International Labour Organization (ILO) and the United Nations Environment Programme (UNEP) that exposed their .git directories and Git credential files. From those files they cloned private repositories, which in turn held database and application credentials for UNEP production systems. Using them, they reached more than 100,000 records about UN staff, including travel histories and HR data. The group reported the flaw privately on 4 January 2021 and published its findings on 11 January. UNEP says it fixed the vulnerability within 12 hours of notification and is not aware of any other unauthorised access or misuse of the data.

Key takeaways

  • The entry point was a machine credential, not a person: a Git credentials file served publicly from a UNEP web server gave access to private, password-protected GitHub projects.
  • The private projects contained seven further credential pairs for UNEP production databases and applications, turning one leaked secret into access to many systems.
  • Researchers reached more than 102,000 staff travel records and thousands of HR, project and evaluation records, according to Sakura Samurai and SecurityWeek.
  • This was responsible disclosure through the UN programme, not a criminal attack. UNEP said the vulnerability was addressed within 12 hours and that it was not aware of other access or misuse.
  • The identity lesson: secrets committed to source code travel with the code, so an exposed repository is an exposed credential store.

At a glance

OrganisationsUnited Nations Environment Programme (UNEP); International Labour Organization (ILO)
WhenReported privately to the UN on 4 January 2021; published by the researchers on 11 January 2021
AttackerNone known. Found by the ethical hacking group Sakura Samurai (Jackson Henry, Nick Sahler, John Jackson and Aubrey Cottle) through the UN vulnerability disclosure programme
Entry pointPublicly reachable .git directories and a .git-credentials file on ILO and UNEP web servers
Identities abusedGitHub credentials for UNEP's private repositories; database and application credentials hard-coded in the code, including WordPress database credentials
ImpactResearchers accessed more than 100,000 UNEP staff records and took over an abandoned ILO database and survey platform; UNEP says it is not aware of other access or misuse
CategoryNHI. Incident class: confirmed NHI breach (exposed Git credentials used by researchers under the UN disclosure programme)

What happened

Sakura Samurai, a group of security researchers, went looking for flaws in systems covered by the United Nations vulnerability disclosure programme and its Information Security Hall of Fame. After enumerating subdomains in scope, they found an ilo.org subdomain that exposed the contents of its .git directory. Using the open-source tool git-dumper, they downloaded the project files and found credentials in the code that let them take over a MySQL database and an administrator account on a survey management platform belonging to the ILO. The group noted that both systems were largely abandoned and held little of value.

Further fuzzing led them to a UNEP subdomain that exposed Git credentials. "Ultimately, once we discovered the GitHub credentials, we were able to download a lot of private password-protected GitHub projects and within the projects we found multiple sets of database and application credentials for the UNEP production environment," the researchers wrote. They found seven additional credential pairs and stopped once they could see personal data in database backups stored in the private projects. BleepingComputer, which reviewed the group's documents, reported that WordPress configuration files exposed database administrator credentials and that other PHP files held plaintext database credentials for UNEP and ILO systems.

The records the researchers reached included more than 102,000 travel records (names, employee IDs, travel justification, dates, approval status and destination), over 7,000 HR nationality and demographic records, more than 1,000 general employee records, over 4,000 project and funding records and evaluation reports on 283 projects. "Overall, in less than 24 full hours we obtained all of this data," the group told BleepingComputer.

The UN initially told the researchers the report concerned the ILO, not the UN Secretariat, according to emails BleepingComputer saw. UNEP then acted. A UNEP spokesperson said: "Upon notification of the breach on 4 January 2021, the vulnerability was addressed within 12 hours. The breached data includes over 100,000 lines of information, including HR and travel details dating from 2015 to 2018." The spokesperson added: "UNEP is not aware of additional unauthorized access to the information nor any misuse of the data." Aubrey Cottle of Sakura Samurai had warned that "if it was this easy to obtain the data, threat actors likely already have the data", a concern that has not been confirmed.

Timeline

DateEvent
4 January 2021Sakura Samurai reports the exposed Git directories and credentials to the United Nations privately.
January 2021UNEP fixes the vulnerability; it later says this was done within 12 hours of notification.
11 January 2021Sakura Samurai publishes its write-up; BleepingComputer and SecurityWeek report the findings.
15 January 2021UNEP tells BleepingComputer it is not aware of additional unauthorised access or misuse of the data.

How it happened: the identity attack path

  1. Exposed repository metadata. Web servers on ILO and UNEP subdomains served their .git directories to anyone who asked, so the full project history could be downloaded with git-dumper.
  2. Credentials in code. The downloaded ILO code contained database and application credentials, which gave control of a MySQL database and a survey platform administrator account.
  3. Leaked Git credentials. A UNEP subdomain exposed a Git credentials file, a stored secret that authenticated to UNEP's private GitHub projects.
  4. Secrets inside private repositories. The private projects held seven more credential pairs for UNEP production databases and applications, plus database backups containing personal data.
  5. Data access. With those credentials the researchers could reach more than 100,000 staff records across several systems before stopping and reporting.

Impact

  • Data accessed by researchers: more than 100,000 records about UNEP staff, including travel history, HR demographic data, pay grades, project funding and evaluation reports, covering 2015 to 2018 according to UNEP.
  • Systems exposed: an ILO MySQL database and survey platform, plus UNEP production databases and applications reachable with the leaked credentials.
  • Misuse: none confirmed. UNEP said it was not aware of additional unauthorised access or misuse, and that the dataset could not be used to attack other UN systems.

What this means for NHI governance

Nothing in this chain needed a stolen password from a person. Every step used a machine credential: a Git credentials file, database logins in configuration files and application secrets in private repositories. Those credentials had no owner watching them, no expiry and no restriction on where they could be used from, so whoever found the first one inherited everything it unlocked.

The case also shows how private repositories become credential stores. Teams treat a private repository as safe, commit a database password to it, and forget it is there. When the repository's own access credential leaks, all the secrets inside leak with it. Moving secrets out of code into a managed vault, scanning repositories and web roots for secrets, and blocking web servers from serving .git directories would each have broken the chain. Our Secrets Management Guide and Public Sector Identity Security Guide cover these controls.

Recommendations

  • Never deploy a .git directory to a web root. Build artefacts should exclude repository metadata, and web servers should deny requests for .git, .env and similar paths.
  • Keep secrets out of source code, including private repositories. Store database and application credentials in a secrets manager and inject them at runtime. See our Secrets Management Guide.
  • Scan code, history and public web content for secrets continuously. Secrets remain in Git history after they are deleted from the latest version, so scan the whole history.
  • Rotate every credential in an exposed repository, not just the one that leaked. Treat all secrets the repository contained as compromised. See the Leaked Credential Response Playbook.
  • Restrict and monitor database access. Limit database logins to known application hosts and alert on connections from anywhere else.
  • Run and resource a vulnerability disclosure programme. The UN programme meant these findings reached UNEP quickly; make sure reports are routed to the right owner the first time.

Frequently asked questions

Was the United Nations hacked in 2021?

Ethical hackers from Sakura Samurai accessed more than 100,000 UNEP staff records in January 2021 through exposed Git credentials, and reported the flaw through the UN vulnerability disclosure programme. UNEP fixed it within 12 hours and said it was not aware of any other access or misuse.

What data was exposed in the UNEP breach?

Staff travel records with names, employee IDs, destinations and dates, HR data including nationality, gender and pay grade, general employee records, project funding records and evaluation reports, dating from 2015 to 2018 according to UNEP.

How did exposed Git credentials lead to the data?

A UNEP web server exposed a Git credentials file. It gave access to private GitHub projects that contained seven more sets of database and application credentials, and those credentials opened the databases holding staff records.

Indian Government Breach 2021 · Emerald Whale Breach · Misconfigured Git Servers Leaking Secrets · Secrets Management Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Exposed repositories and hard-coded credentials are among the most common starting points in our breach database. We help organisations find the secrets they already have in code, move them into managed storage and put owners and rotation in place. See our NHI and AI agent security training.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org