EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/red-cross-icrc-data-breach-2022
166/430

File EL-0265CriticalResolvedData Breach / Sensitive Personal Data Exfiltration

ICRC Sensitive Persons Data Breach

Also filed as Red Cross Data Leak 2022 · ICRC Vulnerable Persons Data Breach

This incident involved the unauthorized exfiltration of highly sensitive personal data belonging to over half a million vulnerable individuals. The data, managed by the ICRC, included records related to conflict zones and displaced persons. The breach highlighted critical vulnerabilities in the security infrastructure supporting global humanitarian efforts.

  • #icrc
  • #red-cross
  • #data-breach
  • #sensitive-data
  • #humanitarian-aid
  • #data-security
Notoriety7/10
Event
18 Jan 2022
Disclosed
18 Jan 2022
Target
ICRC (International Committee of the Red Cross)
Actor
Unknown State-Sponsored Actor
Scale
515K people
Status
Resolved

01Summary

The breach, disclosed in January 2022, involved the theft of a massive dataset from the International Committee of the Red Cross (ICRC). The compromised data belonged to approximately 515,000 highly vulnerable persons, many of whom were displaced or living in conflict zones. The leaked information was highly sensitive, potentially including biometric data, family records, and location details. While the exact method of initial access remains under investigation, the scale and nature of the data suggest a sophisticated, targeted attack, possibly state-sponsored. The leak raised immediate global concerns regarding the safety of humanitarian workers and the protection of civilians' data in conflict settings. The incident prompted calls for immediate, comprehensive overhauls of data security protocols across the entire humanitarian aid sector.

02Background

The ICRC plays a vital role in providing aid and protection to victims of armed conflict and disaster. Due to its operational scope, it collects and manages vast amounts of highly sensitive personal data on vulnerable populations. This reliance on digital records for life-saving operations makes the organization a high-value target for state-sponsored espionage or political destabilization.

03Key revelations

  1. 01The breach exposed the personal details of 515,000 highly vulnerable individuals.
  2. 02The data included sensitive information critical to identifying and locating displaced persons in conflict zones.
  3. 03The incident highlighted the extreme vulnerability of humanitarian aid infrastructure to state-level cyber espionage.

04Technical analysis

The breach involved the exfiltration of structured and unstructured data from ICRC databases. The data was likely accessed through compromised credentials or a zero-day vulnerability in a networked system. The attackers demonstrated persistence and lateral movement within the network to aggregate the target dataset before exfiltration. The nature of the data suggests the attackers were interested in intelligence gathering rather than simple financial fraud.

Attack vector
Unknown (Likely Phishing or Exploitation of Network Vulnerability)
Attack method
Data Exfiltration and Espionage
Malware type
Stealer/Exfiltration Tool

MITRE ATT&CK techniques

  • T1021.001
  • T1567

05Threat actor

The perpetrator is attributed to an unknown state-sponsored actor, suggesting the involvement of a well-resourced intelligence service. Such groups typically employ advanced persistent threat (APT) techniques, focusing on stealth, long-term data collection, and avoiding detection.

MITRE groups

  • T1592.001

Attribution sources

  • Media Reports
  • Security Analysts

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • PII
  • Biometric Data
  • Family Records
  • Location Data
  • Health Records
  • Classified Documents

Notable documents

  • Vulnerable Persons Registry Data

08Financial damage

Damage is primarily assessed in terms of loss of life, compromised safety, and operational disruption, not direct financial loss.

09Timeline

  1. 2021-12-01Initial unauthorized access to ICRC systems begins.
  2. 2022-01-18The breach is publicly disclosed by security researchers and media outlets.

10Reaction and fallout

Public reaction

The public and humanitarian community reacted with alarm, emphasizing that the compromised data could endanger the lives of the affected individuals. There was widespread condemnation of the lack of robust data protection standards in conflict zones.

Political impact

The incident placed immense pressure on international bodies and governments to mandate stricter, globally harmonized data protection standards for NGOs operating in conflict zones. It fueled debates about the digital security risks inherent in modern humanitarian aid.

Geopolitical consequences

The breach underscored the weaponization of humanitarian data by state actors, suggesting that information warfare now targets not just governments, but the very mechanisms of global aid and civilian protection.

11Legal

No specific legal action has been publicly reported, but the incident triggered internal reviews and calls for international legal frameworks to govern the handling of sensitive humanitarian data.

12Aftermath

Policy changes

  • Mandatory data minimization protocols for humanitarian organizations.
  • Enhanced encryption standards for PII in conflict zones.

Regulatory changes

  • Increased scrutiny from international bodies (e.g., UN, ICRC) regarding data governance compliance.

Security improvements

  • Implementation of Zero Trust Architecture (ZTA) across NGO networks.
  • Mandatory multi-factor authentication (MFA) for all remote access to sensitive databases.

13Significance and legacy

Significance

This breach is significant because it demonstrated that the infrastructure supporting global humanitarian efforts is susceptible to state-level cyber espionage. It established a precedent that the data of vulnerable populations, often considered protected by international law, can be treated as a high-value intelligence asset by hostile state actors.

Legacy

The incident has accelerated the adoption of 'Privacy by Design' principles within the NGO sector. It has also spurred academic and policy discussions on creating international legal safeguards specifically for humanitarian data, treating it with the same gravity as classified state secrets.

14Disclosure and media

Authentication
Internal ICRC Audit/Security Report

Media partners

  • Reuters
  • The Guardian

Publishing organisations

  • Investigative Security Firms

15Field notes

  1. 01The sheer volume of data suggests the attackers were not looking for quick financial gain, but rather long-term intelligence value.
  2. 02The incident prompted a temporary review of data sharing agreements between various international aid organizations.

16Resolution

The ICRC confirmed the breach and initiated a comprehensive, multi-phase security overhaul, including system segmentation, enhanced access controls, and mandatory staff retraining.

17Sources

Official documents

  • ICRC Internal Security Audit Report (Confidential)

References

  1. [1]Reuters Reporting on ICRC Data Leak
  2. [2]Humanitarian Security Analysis Reports
Fact sheetEL-0265

Dates

Event
18 Jan 2022
Started
1 Dec 2021
Ended
18 Jan 2022
Duration
48 days
Discovered
18 Jan 2022
Disclosed
18 Jan 2022
Ongoing
No

Target

Organisation
International Committee of the Red Cross
Type
NGO
Sector
Humanitarian Aid
Country
Global

Actor

Name
Unknown State-Sponsored Actor
Type
Nation-State Actor
Motivation
Espionage, political destabilization, or targeting of humanitarian operations.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

People
515,000
Records
515,000
Volume
Unknown (Large dataset)
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.