UN food agency discloses breach affecting 600,000 Gaza households
The World Food Programme (WFP) has disclosed a breach of its self-registration application (SRA) used in Gaza, resulting in the theft of personal data from approximately 600,000 Palestinian households. This incident highlights vulnerabilities within humanitarian organizations and underscores the risk of data compromise in conflict zones. The WFP is actively investigating and implementing security improvements to mitigate further damage.
The breach, discovered on May 14th, targeted the WFP’s SRA system, which is used for registering beneficiaries receiving assistance in Gaza. Attackers gained access to sensitive information including names, ID numbers, phone numbers, and location data collected during the registration process. The WFP has temporarily suspended the registration platform while it implements security enhancements and continues to monitor the situation. The organization is also warning beneficiaries to be cautious of potential scams and suspicious communications. This incident follows a pattern of data breaches affecting UN agencies, including a 2019 attack on UN Geneva offices and a recent 8Base ransomware attack against the UNDP, demonstrating a persistent challenge for international organizations in maintaining robust cybersecurity.