The personal data of approximately 600,000 Gaza households — among the most vulnerable people on earth — has been compromised in a cyber-attack targeting the World Food Programme, The New Humanitarian reported on Tuesday, 2 June 2026. The breach exposed information collected by the WFP as part of its food assistance operations in a territory where nearly the entire population of 2.3 million people now depends on humanitarian aid to survive.

The scale of the exposure is staggering. Those affected include displaced families, children suffering acute malnutrition, and elderly residents who registered with the WFP to receive food rations in a conflict zone where the UN has warned famine conditions have taken hold. For these households, the theft of their data is not an abstract privacy violation — it is a direct physical threat, placing their identities, locations, and vulnerabilities in the hands of actors who may exploit that information for targeting, extortion, or worse.

Humanitarian data breaches carry a particular category of danger that corporate data leaks do not. When the people whose information is stolen are already displaced, living under bombardment, and registered with aid agencies precisely because they have lost every other buffer against harm, a leaked dataset becomes a map of the defenceless. Aid organisations operating in conflict zones routinely collect names, addresses, family composition, disability status, and biometric identifiers — the exact data that armed groups, criminal networks, and hostile state actors find most useful.

This is not the first time the WFP has faced a serious cybersecurity incident. In 2022, the agency acknowledged a breach affecting employee and partner data across multiple countries, prompting internal reviews of its digital infrastructure. But a breach of this magnitude — targeting beneficiary data in one of the world's most active conflict zones — is of a categorically different order. Gaza's communications networks have been severely damaged since October 2023, meaning many of the families affected may have no way of being notified that their information has been exposed, let alone any recourse to protect themselves.

The WFP confirmed the incident, stating that it was investigating the attack and working to determine the full scope of the data compromised. The agency said it had informed relevant authorities and was taking steps to strengthen its cybersecurity posture, without specifying the nature of the attackers, the method of intrusion, or the precise categories of data accessed. Aid sector analysts have criticised that level of disclosure as insufficient given the life-threatening implications for the affected population.

What happens next matters enormously. Humanitarian watchdogs and digital rights organisations are expected to demand a full, independent audit of WFP data systems — not only for Gaza but across its operations in Sudan, Yemen, Syria, and the Democratic Republic of Congo, where similarly sensitive beneficiary registries exist. The breach will also intensify long-running debates within the aid sector about whether centralised digital databases of conflict-affected populations are worth the risk they create, and whether the move toward biometric aid distribution — championed by major donors including the United States and European Union — has outpaced the sector's ability to protect the data it generates.