UN FAO Climate Mapping Tool Allegedly Left Publicly Writable, 138,000 Government Boundary Files Exposed
An actor posting as exfilar claims that two cloud storage buckets belonging to ABC-Map, a geospatial climate adaptation tool operated by the UN Food and Agriculture Organization and funded by the French Development Agency, are publicly accessible with no authentication and no access rules. The buckets are said to hold 138,346 files spanning global government administrative boundary datasets, internal field project data, and contract documents. The significant claim is not the reading but the writing: the actor states the storage accepts uploads and overwrites from anyone on the internet, and reports the condition as live today. The claim is unverified.
▣Post details
!Allegedly included
- Government boundary datasets
- Sub-district boundary data
- FAO project boundaries
- Field plot survey data
- Forestry inventories
- Soil and elevation data
- Fire damage reports
- Grassland classifications
- Contract documents
- Consultant CVs
- Payment terms
- Project staff contact details
- Platform API keys
- Mapping service key
◱Screenshots
⚠Potential impact
Much of the boundary data is openly licensed, so the reading side matters far less than the writing side. Write access to a live UN agency's storage is an integrity problem, not a confidentiality one. Altered boundary files would silently corrupt the climate and biodiversity analyses that governments in developing countries draw on, with no visible sign that anything changed. The same access would permit content to be hosted under a UN-affiliated domain, which carries reputation that security filters and staff both extend trust to, and would equally permit the entire dataset to be deleted. A smaller but real exposure is the contract material, which names project staff and consultants with direct contact details.
iStatus
UnverifiedThe post contains bucket identifiers, API keys, endpoints, and ready-to-run commands for both reading and writing, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor characterises this as a configuration default never changed rather than any intrusion, and states the buckets could be locked at any time. This is the sixth listing from this actor in eight days, all from the same automated scanning operation. Nothing has been independently corroborated. The claim is unverified and the FAO has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE