Faultline Faultline Kommando 161

World · taz · · 2h

Left demands clarification: Who stole the data from Gaza - and why?

Deutsch (original) · Auto-translated to English

The World Food Program (WFP) is vital for the survival of the people in the Gaza Strip; it is the most important pillar for the supply of basic foodstuffs such as bread in the war with Israel. But: In May, the institution, which is part of the United Nations, fell victim to a cyber attack - and suffered the largest data leak in the history of humanitarian aid. This is likely to affect large parts of the population in Gaza. The Left is now criticizing the federal government: Germany must do more to come to terms with it.

Party members had asked the Federal Development Ministry what the government knew about the incident. “The federal government only has limited knowledge of the technical system landscape used by WFP,” says the answer. And further: “WFP is responsible for the manner in which the technical systems used for work are used.”

The left-wing Bundestag member Charlotte Neuhäuser sees it differently. “Hundreds of thousands of sensitive data from a UN organization are being hacked, and the federal government is simply watching: This is grossly negligent and dangerous for those affected,” says Neuhäuser, who is a spokesperson for global justice in her parliamentary group.

On May 14, 2026, hackers broke into the World Food Program (WFP) databases. They stole the personal information of over 600,000 households in Gaza registered with the United Nations agency: names, ID and cell phone numbers, locations.

The WFP does not provide any precise information about how many people are affected. If you calculate with three members per household, 1.8 million people would be affected, almost the entire population. The case is also explosive because it took the WFP over two weeks to inform those affected. It only became public in June.

It is still completely unclear who stole the data and for what purpose. Experts fear that this information can be used by the military or secret services to locate people and, for example, mark them as targets for attacks.

The WFP is silent. Also to the taz. The UN agency did not respond to a query about the incident.

Charlotte Neuhäuser wants the government to use its position as a major donor and executive board member to put pressure on the World Food Program. This should strengthen its cybersecurity. In this context, she also sees the collaboration with the US company Palantir as critical. The WFP uses this to operate the DOTS software platform for managing logistics data in order to plan food transport to crisis areas.

At the same time, Palantir works closely with the Israeli Ministry of Defense and the Israeli Army, providing data analysis and AI-powered systems for military purposes. A risk for people in Gaza, says Neuhäuser. Germany must veto cooperation in the World Food Program.

But: DOTS was not affected by the cyber attack in May. Instead, the data leak affected the app that displaced people in Gaza use to register for food aid. It is not from Palantir.

In its response to the Left's query, the federal government writes that it takes "the possible risks associated with WFP's collaboration with Palantir in the Gaza Strip seriously." However, the UN organization assured the federal government that data access for Palantir, like any other provider, was contractually secured and limited to the information absolutely necessary to provide the service. “No personal information of WFP-supported individuals is processed on Palantir platforms.”

When asked by taz, the Federal Development Ministry wrote that the federal government is “strongly committed to ensuring that the WFP maintains high standards of data protection, data security and digital independence” and “further develops these in the light of new findings”.

There have been indications that this is necessary for a long time. Some of them come from internal reports from the World Food Program, but also from the Federal Audit Office in Germany. He has had a mandate as an external auditor for the WFP since 2022 and has already complained about significant deficiencies in the organization's IT landscape.

But could Germany do more about it? The answer is complicated. After all, Germany cannot decide on the IT processes of a UN institution on its own or ban the use of certain programs, explains Matthias Goldmann, Professor of International Law at the EBS University of Economics and Law in Hesse.

The financial leverage is double-edged. “You could of course say: ‘Okay, we will no longer pay a voluntary contribution to this project if you don’t do this or that,’” said the lawyer. “But then you also have to say: At the end of the day, you are playing with people’s lives, especially with the World Food Program.”

The federal government could, for example, submit an application to the Executive Board of the World Food Program and use its negotiating power. You can try to exert political influence informally. “And of course the states that pay the most have a big influence.” This could also be done to call for an independent commission on the data leak. Germany could also request access to the WFP's IT infrastructure. However, the WFP may refuse to release the information under certain circumstances.

Axel Dreher, who is a professor of international economic and development policy at the University of Heidelberg, sees it similarly. Apart from submitting proposals to the Executive Council, Germany's only option is to attach conditions to voluntary financial contributions. Whether the WFP accepts them is a “matter of negotiation”. In addition, the President of the Federal Audit Office can examine administration and management. The German institution's testing mandate runs until mid-2028.

Read the full story at the source

Source: taz