TL;DR: On May 14, a cyberattack hit the World Food Programme's self-registration system for Palestine, exposing names, national ID numbers, phone numbers, and location data for roughly 600,000 households, people who signed up to receive food and cash aid in Gaza. WFP didn't tell affected families until May 31 and didn't go public until June 2. No attacker has been identified. This is the largest known breach of humanitarian beneficiary data, surpassing the ICRC's 2022 breach of 515,000 records. In an active conflict zone, leaked location data tied to identifiable individuals isn't an inconvenience. It's a survival threat.

What Got Stolen, and From Whom

The attackers compromised WFP's self-registration application (SRA), a platform where Palestinians sign up to receive food and cash assistance. To register, you hand over your name, your national ID number, your mobile number, and your location. You do this because you're hungry and the UN says it needs this data to help you.[1]

That data, for approximately 600,000 households, is now in unknown hands.

WFP described it as a "security-related incident" involving "unauthorised actors." Translation: someone broke in and took everything.[2]

The breach happened on May 14. WFP notified affected families via Telegram on May 31, seventeen days later. The organization went public on June 2.[1][3]

Seventeen days. In a conflict zone where circumstances change by the hour, WFP sat on the knowledge that 600,000 households' locations had been exposed for more than two weeks.

This Isn't a Normal Data Breach

When Ticketmaster leaks your email, you get more spam. When a hospital leaks your records, you worry about identity theft. Those are real problems.

When someone leaks location data tied to national IDs and phone numbers in an active war zone, people can die.

Think about what this dataset contains. Names matched to ID numbers. Phone numbers matched to locations. This is a targeting package. Anyone with access to this data can identify where specific individuals live, how to reach them, and (through the registration records) confirm they're civilians receiving humanitarian aid.[3]

UpGuard's analysis classified the breach as "High" severity, noting that "the leakage of location data and mobile numbers could lead to physical security concerns or harassment via digital channels." That's the sanitized version. The reality is starker: in Gaza, being identifiable and locatable has immediate physical consequences.[3]

The affected population has almost no ability to protect themselves. They can't change their national ID numbers. Many can't change their phone numbers: it's their lifeline for aid coordination. And they definitely can't change their location when they're trapped in a conflict zone with limited movement.

The Registration Trap

Here's the ugly paradox at the center of this breach: to receive humanitarian aid, you have to give up your data. There's no anonymous option. No "I'd rather not share my location." You're starving, the WFP has food, and the price of admission is your personal information.

The self-registration application was built so people could sign up for food and cash assistance after verification. It's a reasonable system in theory: you need to prevent fraud and ensure aid reaches real people.[1]

But it creates a honeypot. Six hundred thousand households' worth of sensitive data, concentrated in one system, in one of the most targeted digital environments on earth. The question isn't whether this system would be attacked. It's why anyone thought it wouldn't be.

WFP says it "took immediate action to shut down the platform, contain the intrusion, and strengthen its security controls." That's the standard post-breach press release. Shut the door after everything's been taken.[1]

Humanitarian Data Breaches: A Pattern, Not an Anomaly

This isn't the first time attackers have gone after humanitarian data. It's not even the biggest shock. It's just the biggest.

In January 2022, the International Committee of the Red Cross discovered that hackers had stolen data on more than 515,000 "highly vulnerable people," individuals separated from families by conflict, missing persons, and people in detention. The data came from the Restoring Family Links programme, which helps reconnect families torn apart by war.[4]

The ICRC breach was described as "highly sophisticated" and comparable to state-sponsored operations. It forced the organization to shut down the Restoring Family Links programme entirely. Robert Mardini, the ICRC's director-general, said: "An attack on the data of people who are missing makes the anguish and suffering for families even more difficult to endure."[4][5]

The WFP breach is bigger (600,000 households versus 515,000 individual records) and arguably more dangerous because of the conflict context. But the pattern is the same: humanitarian organizations collect sensitive data from the world's most vulnerable people, store it in systems that aren't hardened against sophisticated attackers, and then act surprised when those systems get hit.

Humanitarian data is high-value intelligence. Registration databases tell you who is displaced, where they are, and how to reach them. For any party in a conflict (state or non-state) that's gold.

There Are No Rules for This

If your hospital gets breached in the US, HIPAA kicks in. There are notification requirements, penalties, and regulatory consequences. If a European company loses your data, GDPR applies.

What law protects a Gazan household whose food aid registration data gets stolen by unknown attackers?

The short answer: nothing with teeth. International humanitarian law establishes broad protections for civilians, but it wasn't written for the digital age. There's no "Geneva Convention for data." The ICRC has published guidance on the protection of humanitarian data, but guidance isn't enforcement.[4]

WFP has its own data protection policies. But when a breach happens, the affected population has no regulator to complain to, no class action to join, no credit monitoring service that matters when you're living in a conflict zone. The power asymmetry is total: the organization holds your data, the organization lost your data, and you have no recourse.

Who Did This? Nobody Knows. That's the Problem.

As of June 4, no attacker has been identified and no group has claimed responsibility. WFP says an investigation is underway.[1][3]

The lack of attribution isn't unusual for attacks on humanitarian targets. The ICRC's 2022 breach was never publicly attributed either, though analysts noted its sophistication pointed toward state-level capabilities.[4]

The list of parties who'd find a dataset of 600,000 Gaza household locations useful is disturbingly long. And the list of parties with the capability to breach a UN agency's registration system is not short either.

Without attribution, there's no accountability. Without accountability, there's no deterrence. And without deterrence, the next humanitarian database is already a target.

What You Can Do

If You're Affected

WFP notified affected households via Telegram. Be alert for phishing messages, suspicious calls, or anyone requesting further personal information while claiming to represent aid organizations.

Demand Humanitarian Data Standards

Organizations like Access Now and the ICRC are pushing for enforceable data protection standards in humanitarian operations. Support their work.

Push for Data Minimization

Aid organizations should collect only what they absolutely need and delete it when it's no longer required. No one needs a permanent database of vulnerable people's locations.

Watch for Secondary Exploitation

Breached data from conflict zones has historically appeared on dark web markets and been used in targeted operations. Security researchers and journalists should monitor for this dataset surfacing.

The Bottom Line

The WFP asked 600,000 Gaza households to trust it with their most sensitive information. Names, IDs, phone numbers, locations: everything a family needs to receive food, and everything an adversary needs to find them.

That trust was broken on May 14. The data is out. It can't be recalled, and the people it belongs to can't change their identities, their phone numbers, or their locations. They're stuck with the consequences of a security failure they had no power to prevent and no ability to mitigate.

Until humanitarian organizations treat beneficiary data with the same seriousness as classified intelligence (because in a conflict zone, that's exactly what it is), this will keep happening. The ICRC breach in 2022 should have been the wake-up call. Apparently, 515,000 compromised records wasn't loud enough. Maybe 600,000 households will be.

References

  1. The New Humanitarian: Data of 600,000 Gaza households exposed in WFP cyber-attack
  2. Middle East Eye: WFP says cyberattack exposed data of 600,000 Gaza households
  3. UpGuard: World Food Programme data breach exposes sensitive data of 600,000 households
  4. ICRC: Cyber-attack on ICRC: What we know
  5. Al Jazeera: Hackers steal Red Cross data on 515,000 vulnerable people