Share & more
The World Food Programme is re-opening its self-registration app for Gaza aid recipients, more than two months after a cyber-attack exposed sensitive personal information belonging to what appears to be almost the entire population of the enclave.
In a message sent to partner organisations working on responses in Gaza and shared widely this week, WFP announced that the self-registration app, offline since the 14 May cyber-attack, was restarting after the agency had made “improvements to strengthen the security of the system and better protect household information”.
WFP also informed recipients in Gaza in a series of posts on Telegram, the instant messaging app. “Coming soon!!” read a 25 July message, which touted a “comprehensive update of security and privacy procedures”.
But WFP continues to provide little information about the cyber-attack, the vulnerabilities behind it, or the risk the breach poses to people in Gaza, according to aid workers, donors, and rights groups who spoke to The New Humanitarian. The Israeli military has used data in advanced weapons systems to target and kill in its onslaught on Gaza – part of what the world’s leading genocide scholars say amounts to genocide, war crimes, and crimes against humanity against Palestinians.
“WFP has data on the whole Strip, and there are a limited number of people. It’s not only WFP beneficiaries. That’s why we wanted to have a clear picture of the impact,” said a humanitarian who works on responses in Gaza and the West Bank, and asked not to be named in order to speak freely.
The digital rights group Access Now had called on WFP not to restart the self-registration app – and not to ask for or process new data – until the potential harms could be identified and mitigated, and until mass data collection could be justified given the risks.
“There is literally no reason not to be transparent,” said Giulio Coppi, the group’s senior humanitarian officer. “It’s disappointing to see such an important actor behaving so poorly in terms of accountability to affected populations, and also accountability to the overall sector.”
“Do not provide technical explanations about previous security incidents unless directed by approved WFP messaging. Focus on improvements and current access.”
The self-registration updates appear to include asking people for a six-digit PIN, an SMS verification code, and an additional “security check”, according to an info sheet written for frontline staff and seen by The New Humanitarian.
“Do not provide technical explanations about previous security incidents unless directed by approved WFP messaging,” the document advises. “Focus on improvements and current access.” There’s no advice about what to tell people who are worried about the risks of having their data exposed.
The New Humanitarian sent WFP questions about the registration app’s restart, the status of any investigation into the cyber-attack, what WFP has done to assess risks to beneficiaries, and the total number of people exposed, among other issues.
In a reply sent on 29 July, WFP did not respond to questions but shared a link to a PDF document addressed to partners. “Detailed and dynamic third-party scans have been conducted, and the overall security posture has been strengthened to ensure the highest level of cyber protection currently available,” the update states.
It was the agency’s first reply to questions from The New Humanitarian since 3 June.
Little information for aid partners or donors
WFP says the 14 May cyber-attack exposed data belonging to 600,000 households. It confirmed the breach publicly to The New Humanitarian on 2 June, saying “unauthorised actors” accessed data such as names, ID and mobile numbers, and neighbourhood location data.
WFP has indicated that an investigation is under way, but has disclosed no findings, risk assessments, or a timeline to do so.
It has also refused to confirm how many people are affected. Typical household sizes in Gaza – various counts estimate between 3.6 and 5.5 – suggest nearly all of Gaza’s population was exposed. WFP earlier said that more than 2 million people in Gaza had submitted their info to the self-registration app, known as People Portal. Gaza’s remaining population is roughly 2 million people.
WFP appears to have made no public statements about the attack, other than responding to The New Humanitarian’s initial questions.
“I think it’s textbook WFP – just being very defensive on the fact that they did their homework and they don’t have to report back to anyone.”
The reluctance to discuss the issue publicly is mirrored behind closed doors, where even aid workers and donors say the agency has been frustratingly tight-lipped.
“The narrative has been they’re handling it as well as they can – that they did the right thing to bring in an independent third-party investigation,” said a source in the donor community, who asked not to be identified as they were not authorised to speak publicly.
But information is rarely volunteered, what has been shared is scant, and there’s “certainly no recognition of the potentially catastrophic impact on Gazans”, the source said.
Aid workers who engage with WFP in Gaza described similar interactions.
“The response was quite aggressive, saying they would share when ready,” said the humanitarian working on responses in Gaza and the West Bank. “I think it’s textbook WFP – just being very defensive on the fact that they did their homework and they don’t have to report back to anyone.”
Data collection, AI, and Palantir under the microscope
The cyber-attack and WFP’s actions in its aftermath point to broader worries around security, Big Data, and rapidly advancing artificial intelligence across the aid sector.
Deep donor funding cuts are also pushing aid groups to pursue AI and tech solutions – without the shared guardrails and guidelines to ensure risks are minimised and that people in crisis have a voice, technologists and privacy experts say.
WFP, in particular, has sought to grow its global beneficiary ID management programme, known as SCOPE, and transform into a “data-driven entity” that leverages data across the UN and the humanitarian system. Its partnership with the military contractor Palantir is drawing deep and growing criticism from UN rights watchdogs, donors whose governments are dropping or weighing contracts with Palantir, and civil society.
Palantir’s software backstops WFP’s backend data integration capabilities – and bolsters the Israeli military algorithmic targeting systems. The company is also named in UN special rapporteur Francesca Albanese’s “economy of genocide” report on the corporations that sustain Israel’s “displacement and replacement” of Palestinians.
For now, WFP’s perceived silence continues to frustrate some humanitarians working on the response in Gaza.
Other aid organisations need to know more in order to fortify their own systems and to ensure protections are adequate. After the cyber-attack, other organisations also shut down their own registration systems as a precaution, one aid worker noted. It’s unclear whether they will resume, even while WFP reboots theirs.
“There are two million people in the Gaza Strip. We cannot pretend that nothing has happened,” said the humanitarian who works on responses in Gaza and the West Bank. “It’s our responsibility to take stock and fix the issue. The issue has been created by our systems.”
Edited by Andrew Gully.
Facts Only
* The World Food Programme re-opened its self-registration app for Gaza aid recipients.
* This occurred more than two months after a cyber-attack exposed sensitive personal information.
* WFP announced the restart after making "improvements to strengthen the security of the system."
* WFP informed recipients in Gaza about updates to security and privacy procedures via Telegram.
* The cyber-attack occurred on May 14th.
* WFP stated the cyber-attack exposed data belonging to 600,000 households.
* The leaked data included names, ID, mobile numbers, and neighbourhood location data.
* WFP indicated an investigation is underway but disclosed no findings or risk assessments.
* Typical household sizes in Gaza suggest nearly the entire population was exposed.
* WFP previously reported that over two million people had submitted information via the People Portal.
* The self-registration updates reportedly involve a six-digit PIN, an SMS verification code, and an additional "security check."
Executive Summary
Full Take
Sentinel — Human
The text functions as a journalistic investigation, balancing official statements with critical commentary from human rights groups, pointing toward systemic accountability failures regarding data security and AI use in humanitarian aid.
