The World Food Program's Data Breach in Gaza: Protecting Palestinians’ Data Means Protecting Palestinian Lives
Read in Arabic / للقراءة بالعربية
On 14 May 2026, a cyberattack compromised the World Food Programme's Self-Registration Application (SRA) for Palestine, exposing the personal data of at least 600,000 Palestinian households in Gaza, including names, ID numbers, phone numbers, and location data. With over 2 million people registered in the app, this may represent the largest known breach of humanitarian beneficiary data in history. WFP waited 17 days before notifying affected individuals, via a Telegram message, and has to date provided little information about the full scale of the breach, the steps it is taking in response, or whether a risk assessment has been conducted.
Skyline International for Human Rights (SIHR) condemns this breach in the strongest possible terms and urgently calls on WFP to be fully transparent and to take all necessary measures to prevent further harm. Gaza is a place where data has long been weaponised against Palestinians, turned against the very people it was supposed to protect, and it is within that reality that this breach must be understood.
A pattern of warnings ignored
WFP has a documented record of data protection shortcomings that stretches back years. A 2017 internal audit of WFP's flagship beneficiary management system, SCOPE, found that the agency needed major improvement in how it safeguarded beneficiary data and that policies designed to protect data and privacy had not been effectively implemented. By 2021, SCOPE held 63.8 million registered identities across 80% of the countries where WFP had a presence, with little evidence that the structural problems identified in 2017 had been resolved. Critically, a 2022 audit of WFP's Palestine operations found specifically that risks related to personal data collection had not been assessed or mitigated due to limited internal technical capacity. That audit was completed four years into WFP's expansion of digital registration tools in Gaza. The SRA breach happened anyway.
The agency has also faced sustained criticism for its partnership with Palantir, a data analytics firm with deep roots in U.S. military and intelligence surveillance operations, and named in a report by the UN Special Rapporteur on the occupied Palestinian territory among companies accused of sustaining Israel's occupation of Palestine. For a humanitarian organisation operating in Gaza, partnering with a company of this profile raises serious questions about whose interests are ultimately served by the data WFP holds, who has access to it, and under what contractual arrangements, and whether such partnerships are compatible with the protections humanitarian actors are afforded under international law. In Gaza, the consequences of getting this wrong are measured in lives.
A population already under the lens
For Palestinians, the exposure of personal data goes far beyond privacy. It has been a matter of physical safety for years, and the stakes have never been higher than now. Israel has built one of the most sophisticated surveillance architectures in the world, developed and tested on Palestinian communities, and integrated directly into military targeting operations in Gaza.
Investigations by +972 Magazine and Local Call revealed the use of AI systems including Lavender, which at one stage generated a kill list of up to 37,000 Palestinians, and Where's Daddy?, which tracked individuals' movements to identify when they were at home in order to strike them there. Military sources cited in that investigation stated that the principle of proportionality effectively did not exist in the early weeks of the war. Human Rights Watch has documented how these tools rely on mobile phone location data, machine learning, and algorithmic processes that are technically impossible to scrutinise and highly susceptible to bias and error.
The data exposed in the WFP breach, names, ID numbers, household compositions, health information, displacement histories, and exact locations, is precisely the kind of information that has fuelled this targeting. WFP's apparent assessment that it is unaware of any misuse or exploitation of the data is not reassuring in this context. It is alarming.
Data Collected Under Coercion
SIHR has long documented the way in which data collection in Gaza has been structured as a condition of survival rather than a matter of genuine choice. Through our briefing "The Price of a Meal: Forced Biometric Surveillance and Military Control of Humanitarian Aid in Gaza,” , we documented how the Gaza Humanitarian Foundation (GHF), a U.S. and Israeli-backed entity that has replaced much of the UN-led aid architecture in Gaza, has deployed facial recognition cameras and drones at distribution points, with footage fed to joint U.S.-Israeli control rooms. Palestinians who refuse to submit to biometric data capture risk exclusion from food assistance. That is not consent. That is coercion.
The WFP's SRA operated on the same structural logic. The app required individuals to submit and regularly update names, dates of birth, phone numbers, marital status, the names and ID numbers of all family members, health status including pregnancies and disabilities, current place of residence or displacement, and the number of times they had been displaced since 7 October 2023. This is an extraordinarily detailed profile of an entire population, collected under conditions of war and genocide. As is now broadly recognised, consent alone is not a sufficient legal basis for collecting highly sensitive data in conflict settings where people face an impossible choice between surrendering their personal information and going without food. More than 2 million people registered in the SRA. They did so because they were starving.
Notification that could not reach its recipients
The 17-day delay in notifying affected individuals cannot be separated from the reality of connectivity in Gaza. Israel fully controls Palestinian telecommunications infrastructure and, under the Oslo Accords, Palestinians have been denied the right to develop their own. Since 7 October 2023, Access Now has documented at least 23 internet shutdowns in Gaza, each coinciding with periods of intensified military operations, and by December 2023 all major communication networks in Gaza had been destroyed. Notifying a besieged, displaced, and largely disconnected population via Telegram, 17 days after a breach of this magnitude, is not meaningful notification. For the majority of those affected, it may have been no notification at all.
Accountability, not just transparency
Calls for WFP to be transparent about this breach are necessary. But transparency alone is not accountability, and for Palestinians it is not enough. The people whose data was exposed have no functioning legal system to appeal to, no data protection authority to complain to, and no means of knowing whether or how the exposed information has been accessed or used.
SIHR calls on WFP to immediately impose a moratorium on the reactivation of the SRA for Palestine until a comprehensive, independent, and context-specific risk assessment has been completed and its findings made public. We call on WFP to commission a full independent investigation into the breach, disclose the precise number of individuals affected, and take active steps to understand and mitigate the risks to people in Gaza.
We call on the humanitarian sector more broadly to recognise that collecting extensive personal data from a population living under occupation, genocide, and active military surveillance carries consequences that go far beyond data management. WFP was warned in 2017 and again specifically about its Palestine operations in 2022. Neither warning translated into action. The question the sector must now answer is not only what went wrong but also why warnings that were specific, documented, and repeated were not acted upon and who is accountable for that failure.
Donors and governments must require their humanitarian grantees to conduct independent audits of their data practices in Gaza and other high-risk conflict settings, to publish those findings, and to cease collection of sensitive personal data where risks cannot be adequately mitigated.
Palestinians in Gaza did not choose to be catalogued. They chose to eat.