Issue #134

WFP Gaza App Hack Leaks 600,000 Households' Data

A hacked Gaza aid registration app exposed residents' data, raising the question of how much information relief actually requires.

SocietyWFP Gaza App Hack Leaks 600,000 Households' Data

The Danger When Leaked Data Is a Location

Korea has seen its own string of data breaches at telecom carriers and retailers. Leaked information can lead to more than spam and phishing—it can cause financial harm and threaten personal safety. In conflict zones, the very same kind of information can create far more immediate danger.

Reports emerged that a hack of the UN World Food Programme (WFP)‘s Gaza aid registration app leaked data belonging to roughly 600,000 households. The exposed data included names, ID numbers, phone numbers, and the neighborhood where each person was living at the time of registration. That’s not the same as leaking a precise home address or real-time location—but simply knowing someone’s identity alongside their general area of residence is enough to cause serious anxiety for the people affected.

To apply for food and cash assistance, applicants have to submit personal information. For residents desperate for aid, there’s little room to refuse registration. That places the responsibility squarely on relief organizations: how much of this data they collect, who gets to see it, and when it gets deleted.

Names, ID Numbers, and Neighborhoods Leaked Together

On May 14, the WFP’s Self-Registration App (SRA) was hacked. This is the system Gaza residents use to register directly for food and cash assistance. The verification process for confirming identity and eligibility collects a substantial amount of personal data. The leaked information included names, ID numbers, mobile phone numbers, and neighborhood-level residential locations recorded at the time of registration.

According to reports, the WFP was at the time providing monthly food and cash assistance to roughly 1.6 million people in Gaza — about 77% of the entire population. The 600,000 leaked households and the 1.6 million monthly aid recipients are figures counted on different bases. When so many residents depend on aid, the security of a registration system for that aid carries a far heavier responsibility than security for an ordinary service.

There had already been a warning before the hack happened.

An independent security researcher warned the WFP’s Palestine team about a system vulnerability on May 12 — two days before the hack occurred. Yet the WFP didn’t notify beneficiaries of the breach until May 31, 17 days after the hack. According to a whistleblower, in the interim the WFP conducted no risk assessment and showed no effort to mitigate the security risks facing Gaza residents.

The WFP announced via Telegram that the assistance program would continue and that there was no need to delete or re-register information. The registration platform was temporarily suspended to strengthen security. As of reporting, the attacker’s identity and the ultimate fate of the leaked data remained unconfirmed. Assuring people that aid will continue is a separate matter from guaranteeing that their personal data is safe.

How Much Information Does Aid Verification Actually Require?

Confirming who qualifies for aid and cutting down on duplicate distribution does require some data collection. But the more categories of information collected—and the longer they’re retained—the greater the damage when a breach occurs.

The WFP manages roughly 63.8 million identity records across 80 countries through SCOPE1, its beneficiary management system. Some programs handle biometric data as well. This is a separate system from SRA, the self-registration app that was hacked in this incident. The SRA breach should not be conflated with a compromise of SCOPE as a whole, nor should it be read as a leak of fingerprint or iris data.

The WFP’s data privacy practices have drawn scrutiny in past audits, too.

The New Humanitarian reported that audits in 2017 and 2021 found the WFP’s data management required major improvements. A 2022 audit of the Palestine office likewise flagged shortcomings in risk assessment and mitigation around personal data collection, as well as gaps in internal technical capacity.

It’s worth checking how much progress was actually made on those earlier findings. But whether the flaws identified in prior audits directly caused this hack—or whether nothing was done in the interim—is a separate question that needs its own evidence. Repeated warnings alone don’t tell us the attack vector.

There’s also controversy around the WFP’s technology vendors. In 2019, the WFP entered a five-year, $45 million technology partnership with Palantir. The WFP has described the collaboration as an effort to integrate supply-chain and operational data to reduce the cost of aid delivery. Because Palantir also supplies technology to military, intelligence, and immigration-enforcement agencies, human rights groups have raised concerns about who can access beneficiary data and how far it might be reused.

How a partnership with a company also engaged in military and surveillance work affects a humanitarian organization’s neutrality is a serious question. But using the same vendor’s software is not, by itself, evidence that the WFP shares beneficiary data with military or intelligence agencies. Vendor selection, data-access permissions, and contractual restrictions each need to be examined separately.

Reporting aid outcomes to donors and reducing duplicate payments are legitimate needs. That doesn’t mean every beneficiary’s biometric data has to be collected. Even names or ID numbers require a defined purpose and retention period. The benefit of delivering aid accurately has to be weighed against the risk residents bear if that information is leaked.

When Hacking Overlaps With Demands for Personal Data in Conflict Zones

What makes this leak especially dangerous is that the people whose information was registered are living in the middle of a war zone.

In Gaza, residents who went out to collect aid supplies have been killed. Even receiving food is not a safe act. If information linking names to home neighborhoods leaks, the risk grows that it could be used to identify or track residents. As of the time of reporting, it had not been confirmed whether this particular data was actually used in an attack.

The danger of data held by aid organizations has surfaced in other incidents as well.

In January 2022, the ICRC disclosed that the personal data of more than 515,000 users of its humanitarian services — including its family-reunification program — had been compromised. The investigation found that the attack began in November 2021 and exploited a vulnerability for which a security patch had not yet been applied. The ICRC described it as a sophisticated, targeted attack but did not name a perpetrator.

In 2021, concerns arose that biometric devices and identity databases left behind after the change of regime in Afghanistan could be exploited to identify local collaborators. It’s worth distinguishing between the data stored on the devices themselves and the full records kept on separate servers.

The case of information-sharing involving Rohingya refugees was a different kind of problem — not hacking. Human Rights Watch pointed out in 2021 that data collected by UNHCR and Bangladesh had been passed on to Myanmar without adequate explanation or consent. UNHCR denied any violation, saying it had explained the purpose and obtained consent. This case shows that even when data is stored securely, residents and institutions can still disagree sharply over who it’s shared with and how consent is obtained.

Submitting staff information is also a point of contention. On 20 May 2026, Israel’s Supreme Court rejected a petition filed by international aid organizations against new registration and security regulations — rules that, among other things, require the submission of lists of Palestinian staff. The aid groups objected on the grounds that staff could become targets of retaliation, and the ruling gave them a 30-day deadline to comply with the relevant obligations.

The aid organizations argued that, with staff already dying during the war, handing over name lists could increase the danger. They proposed alternatives such as independent vetting or donor audits, but these were not accepted. The clash is between states demanding security screening and aid organizations obligated to protect staff safety and neutrality.

Aid organizations need data to prove the results of their assistance work; governments demand data for security vetting. On top of that, there’s the risk of hacking. Both residents and staff have little way of knowing how far the information they submit actually travels.

Oswarld’s Lens

From my experience shaping tech management strategy, data collection often gets treated as a precondition for doing business at all — you need data to understand customers and to demonstrate results. But whether retention periods and deletion responsibility get the same weight as collection purpose in those planning meetings is a separate question worth examining. Watching this incident unfold made me reconsider that point myself.

I believe strengthening security has to go hand in hand with deciding, from the outset, what information not to collect.

The ICRC’s biometric data policy offers a useful reference point here. This wasn’t a response drafted after the 2022 hack — it’s a policy adopted in 2019. For identity verification purposes, it proposed storing biometric data on the beneficiary’s own card rather than having the ICRC build a central database. Work with separate needs, like family tracing, was handled distinctly. This wasn’t a wholesale rejection of data collection — it was a matter of varying the method and scope of collection according to purpose.

Even when I’m working on GTM strategy, this makes me think we shouldn’t treat collected data purely as a business asset. Stored information carries storage costs and breach liability with it. This is especially true when the people being registered are in no position to refuse — in those cases, the collecting party needs to hold itself to a stricter standard. Principles like collecting only what’s necessary, limiting who can access it, and deleting data once its purpose has been served need to actually be built into operations, not just stated.

Closing

We still need to confirm the exact attack path behind the WFP breach and whether past audit findings were ever properly addressed. But for the residents whose registration data was exposed, the risk doesn’t wait for the investigation to conclude. The first step has to be telling them plainly what information was leaked and what help is available to them now.

Aid efficiency and privacy protection need to be designed together. Figuring out exactly what information is truly necessary for delivering aid — and making sure that information can’t later be used against the very people it was meant to help — should be considered part of the job of humanitarian work itself.

💬 What do you think about a system where people have to hand over personal data just to receive help? Share your thoughts in the comments.

Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References

Primary sources

Background

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

Footnotes

  1. SCOPE: A beneficiary identity and assistance management system developed in-house by WFP. It has been in operation since 2014 and manages roughly 63.8 million identity records across 80 countries. This includes biometric data such as fingerprints, iris scans, and photographs. Internal audits in both 2017 and 2021 gave it consecutive “major improvement needed” ratings.