World Food Programme Breach Exposes Data of 600,000 Gaza Households in What Researchers Call the Largest Known Hack of Humanitarian Beneficiary Records
A cyberattack on the UN World Food Programme's Palestine registration app exposed personal data of about 600,000 Gaza households, drawing criticism over a 17-day notification delay.
Overview
The United Nations World Food Programme (WFP) has disclosed that a cyberattack on the system Palestinians in Gaza use to register for food and cash assistance exposed the personal data of approximately 600,000 households, according to BleepingComputer. The compromised platform, the agency’s Self-Registration Application (SRA) for Palestine, is the channel through which Gazans submit their information to receive aid, as reported by The Register.
Digital-rights group Access Now describes the incident as what may be “the largest-known breach of humanitarian beneficiary data to date,” according to Access Now — a characterization echoed by UpGuard, which called it “the largest breach of its kind to date.”
What We Know
The breach occurred on May 14, 2026, according to BleepingComputer, which reports that around 600,000 Palestinian households in Gaza were affected. UpGuard independently puts the breach date at May 14, 2026 and the count at approximately 600,000 households.
The exposed information included names, ID numbers, phone numbers, and location information such as neighborhood data recorded during registration, according to BleepingComputer. The Register lists the same categories — names, ID numbers, phone numbers, and location information.
Access Now describes a substantially broader set of fields registered through the SRA, including date of birth, marital status, the names and ID numbers of family members, health status such as pregnancies and disabilities, and displacement history dating back to October 7, 2023. The same group reports that more than 2 million people had registered through the application.
WFP supports 1.6 million Palestinians every month, according to The Register. The agency temporarily suspended the registration platform to apply security improvements, the same outlet reports.
In a statement, WFP told aid recipients: “We understand this may be concerning, and we want to assure you that protecting your data and privacy is our top priority,” as reported by The Register. A later update added that “food assistance, cash assistance, nutritional supplementation, and all other WFP programs are continuing as usual,” according to the same report.
The Notification Timeline
According to Access Now, the cyberattack took place on May 14, 2026, but WFP did not notify affected people — via a message sent over Telegram — until May 31, 2026, a gap of 17 days. BleepingComputer likewise reports that WFP’s notice reached aid recipients through Telegram.
Access Now sharply criticized that delay. “This delay not only falls short of best practices for breach notifications but also puts the safety of people at risk,” the group said, according to Access Now. The same statement added that the organization was “further appalled by WFP’s apparent dismissal of the risks posed by the breach.”
What We Don’t Know
The attacker or cause of the incident has not been identified, according to UpGuard, and no party has claimed responsibility, as reported by BleepingComputer. The precise number of individuals affected — as opposed to households — remains unclear, though Access Now notes that names and ID numbers were collected for every household member, implying the true figure is far higher than the household count.
Analysis
The breach is notable less for its technical sophistication — none has been disclosed — than for the extreme vulnerability of the people whose data was exposed. Access Now argues that “the data exposed in this breach is exactly the kind of information that fuels the targeting of civilians,” framing the incident against what it calls systematic population surveillance in Gaza.
The group also challenges the legal and ethical basis for collecting such sensitive records in a conflict zone in the first place, stating that “consent alone is not a sufficient legal basis for collecting highly sensitive data in conflict settings,” according to Access Now. It has called for an immediate moratorium on reactivating the SRA until a comprehensive risk assessment is completed.
For an agency that, by The Register’s account, supports more than a million and a half Palestinians a month, the episode underscores a tension at the heart of modern humanitarian operations: the same digital registration systems that make aid delivery efficient also concentrate uniquely sensitive data on populations least able to absorb the consequences of its exposure.