WFP Breach Exposes Gaza Aid Data
Coverage from The New Humanitarian, Access Now, and others

The World Food Programme’s Palestine Self-Registration Application was breached on 14 May 2026, exposing personal information associated with Palestinian households seeking food and cash assistance in Gaza.
Reported data included names, identification numbers, phone numbers, and location details, with WFP citing approximately 600,000 affected households while the total number of potentially exposed users remains unclear. The incident has prompted criticism over the 17-day notification delay, limited public disclosure, and the collection and protection of highly sensitive data in an active conflict environment.
The core breach story is largely unchanged, but the current version adds clearer detail on the exposed data, the response, and the broader scrutiny now extending to WFP’s technology relationships. It also softens some uncertainty by reaffirming the 17-day notification delay and by noting WFP’s claim that the breached system was not connected to Palantir.
The story shifted from a reported Gaza registration breach to a more specific WFP disclosure identifying the May 14 incident, the platform affected, and the approximate scale of impacted households. The current version also adds more concrete response timing and clarifies that scrutiny of Palantir is separate rather than tied to the breach.
