Skip to content

UN FAO Climate Mapping Tool Allegedly Left Publicly Writable, 138,000 Government Boundary Files Exposed

Breach Report International Organisation UN Agency / Climate Data Reported Live

UN FAO Climate Mapping Tool Allegedly Left Publicly Writable, 138,000 Government Boundary Files Exposed

An actor posting as exfilar claims that two cloud storage buckets belonging to ABC-Map, a geospatial climate adaptation tool operated by the UN Food and Agriculture Organization and funded by the French Development Agency, are publicly accessible with no authentication and no access rules. The buckets are said to hold 138,346 files spanning global government administrative boundary datasets, internal field project data, and contract documents. The significant claim is not the reading but the writing: the actor states the storage accepts uploads and overwrites from anyone on the internet, and reports the condition as live today. The claim is unverified.

StatusReported live
AccessRead and write
Files138,346
Actorexfilar

Post details

TargetABC-Map, UN FAO
RegionInternational, global datasets
SectorUN agency / Climate data
ListingFree, open bucket
Volume138,346 files, 11GB
CauseClaimed misconfiguration
Observed
Actorexfilar

!Allegedly included

  • Government boundary datasets
  • Sub-district boundary data
  • FAO project boundaries
  • Field plot survey data
  • Forestry inventories
  • Soil and elevation data
  • Fire damage reports
  • Grassland classifications
  • Contract documents
  • Consultant CVs
  • Payment terms
  • Project staff contact details
  • Platform API keys
  • Mapping service key

Screenshots

Potential impact

Much of the boundary data is openly licensed, so the reading side matters far less than the writing side. Write access to a live UN agency's storage is an integrity problem, not a confidentiality one. Altered boundary files would silently corrupt the climate and biodiversity analyses that governments in developing countries draw on, with no visible sign that anything changed. The same access would permit content to be hosted under a UN-affiliated domain, which carries reputation that security filters and staff both extend trust to, and would equally permit the entire dataset to be deleted. A smaller but real exposure is the contract material, which names project staff and consultants with direct contact details.

iStatus

Unverified

The post contains bucket identifiers, API keys, endpoints, and ready-to-run commands for both reading and writing, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor characterises this as a configuration default never changed rather than any intrusion, and states the buckets could be locked at any time. This is the sixth listing from this actor in eight days, all from the same automated scanning operation. Nothing has been independently corroborated. The claim is unverified and the FAO has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest