All Breaches
May 14, 2026 Verified Sensitive Record Humanitarian Aid

WFP Gazze SRA 2026 Data Breach

The WFP Gaza SRA 2026 data breach is an incident in which the United Nations World Food Programme confirmed that unauthorized actors accessed its Palestine-specific Self-Registration Application. WFP said the attack occurred on May 14, 2026, and data connected to approximately 600,000 households in Gaza was stolen. The disclosed fields are names, identification numbers, mobile phone numbers, and location or neighborhood information.

WFP warned users through its official Gaza Telegram channel on May 31, and The New Humanitarian published direct confirmation and incident boundaries from the agency on June 2. BleepingComputer separately reported WFP's statement and user warning. Because the disclosed figure of 600,000 represents households rather than unique people, LeakData keeps pwnCount at zero as an unknown person total.

How Was the Incident Confirmed?

WFP confirmed to The New Humanitarian that unauthorized actors accessed the Self-Registration Application used for Palestine and obtained personal data. The agency said the incident happened on May 14, that it shut down the platform, contained the breach, and opened an investigation. This statement is sufficient to classify the event as a verified data breach rather than only a possible vulnerability or an attacker claim.

The official Telegram notice told applicants that names, identification numbers, phone numbers, and location details may have been obtained by unauthorized parties. Public information does not identify the attacker, initial access path, exploited vulnerability, or technical method used to remove the data. The record therefore attributes the event to no group, government, malware family, or exploit technique.

What Data Was Accessed?

The confirmed data classes are applicants' names, identification numbers, mobile phone numbers, and location or neighborhood information. Together, these fields can identify people receiving humanitarian assistance or registering for aid and indicate the area where they live. LeakData includes only categories explicitly listed by WFP and does not add unconfirmed dates of birth, emails, passwords, bank accounts, payment cards, or health information.

WFP's statement did not specify whether every accessed record contained the same fields or whether every record was copied. “Approximately 600,000 households” also does not mean that every individual in each household had a separate record. Although the data classes are confirmed, the row count, unique-person count, and extraction rate for each field remain undisclosed, so the record preserves those distinctions.

What Does the 600,000-Household Figure Mean?

The figure reported by The New Humanitarian from WFP is approximately 600,000 Palestinian households in Gaza. A household may contain multiple people, while some applications may be held through one contact person for a family. Recording 600,000 as the number of unique affected people in pwnCount would therefore introduce false precision and could understate or overstate the real person total.

LeakData uses zero for pwnCount and totalRecords to indicate that the number of people or records is unknown; this does not mean no one was affected. The household scope is preserved separately in the title, narrative, and source notes. If WFP later publishes a deduplicated person or record count, the numeric fields can be updated from that new evidence.

Boundary Between SRA and Other WFP Systems

The breach is limited to the Self-Registration Application that WFP said was used only in Palestine. The agency stated that its SCOPE assistance-management platform and other WFP systems were not affected. This record should therefore not be read as compromise of WFP's global beneficiary database, records in other countries, or the agency's entire infrastructure.

The public statement does not identify SRA's hosting provider, software components, or the involvement of any third party. Knowing the application name does not establish responsibility for a particular cloud service or vendor. Because the technical root cause and chain of responsibility remain undisclosed, the record reports only the confirmed application boundary, data classes, and geographic impact.

WFP's Response and Continuity of Aid

WFP said it temporarily shut down the SRA platform after the incident, contained the breach, and strengthened security measures. The agency also opened an investigation and warned the affected community through official channels. These disclosed response actions are intended to limit the event; they do not mean the investigation has identified the attacker or exact technical method.

The agency said applicants did not need to register again and that food and cash assistance would continue. Users were warned about people impersonating WFP, fraudulent aid messages, and links seeking personal information. The combination of identity, phone, and location data may increase targeted phishing, social engineering, and aid-themed fraud risk, although no specific case of misuse was disclosed.

How to Interpret This LeakData Record

This record establishes that unauthorized access occurred in the Palestine SRA application on May 14, 2026, and that personal data connected to approximately 600,000 households in Gaza was stolen. It does not provide a unique-person total, total row count, or the number of individuals represented by each household. The critical sensitivity assessment reflects the combination of verified identity and location data in a humanitarian-aid context.

The verified conclusion is that WFP reported the taking of names, identification numbers, phone numbers, and neighborhood or location information from its Palestine-specific SRA system; it shut down the application, contained the event, and said other WFP systems were unaffected. The attacker, technical entry method, unique-person total, and field coverage per record remain unknown. Those uncertainties define the evidence-based limits without diminishing the seriousness of the confirmed event.

0
Affected Accounts
4
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

4
Names
Identification numbers
Phone numbers
Location and neighborhood information

Additional Information

Added DateJuly 27, 2026
Breach DateMay 14, 2026
Domainwfp.org
SourceUnauthorized access to Palestine Self-Registration Application
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information