Bleepingcomputer WFP Cyberattack Exposes Data of 600,000 Gaza Households
Article Content
- •A cyberattack on WFP exposed data of around 600,000 Gaza households.
- •The breach involved unauthorized access to the self-registration application for aid.
- •An anonymous whistleblower warned of vulnerabilities just before the attack occurred.
The UN's World Food Programme (WFP) reported a cyberattack that compromised personal data of approximately 600,000 households in Gaza. The breach, detected on May 14, involved unauthorized access to the self-registration application used for aid registration, exposing names, ID numbers, phone numbers, and location data. An anonymous whistleblower had warned the WFP of vulnerabilities in the system two days prior to the breach. The WFP has temporarily suspended the registration platform to enhance security measures and is currently investigating the incident. No group has claimed responsibility for the attack, and the WFP continues to monitor the situation. Beneficiaries have been advised to be cautious of potential phishing attempts related to the breach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track 8Base and United Nations in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's Hybrid Warfare Threatens UK with Cyberattacks and Sabotage Russia has escalated threats against the UK following its support for Ukraine, warning of 'consequences' for British involvement. Concurrently, Russian-linked cyberattacks, including a ransomware attack on the pathology lab Synnovis, have severely disrupted NHS services in London, affecting over 800 operations and 700…
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…