Hackers leak credentials of WHO and Gates Foundation employees

Almost 25,000 email addresses and passwords allegedly belonging to employees of leading health organisations such as the World Health Organisation (WHO) and the US National Institutes of Health (NIH) have been leaked online in what is being described as a “harassment campaign”.

The news comes as WHO reported that it has been forced to double its security resources due to a significant increase in cyber attacks on the organisation since mid-March when the coronavirus moved up to pandemic status.

Director of SITE Intelligence Group Rita Katz told the Washington Post that “Neo-Nazis and white supremacists capitalized on the lists and published them aggressively across their venues (...) calling for a harassment campaign while sharing conspiracy theories about the coronavirus pandemic”.

Other victims of the breach include the Centers for Disease Control and Prevention (CDC), the World Bank, the Gates Foundation and the Wuhan Institute of Virology, who all had their credentials posted to sites such as 4chan and Pastebin.

According to SITE, which was unable to verify whether the email addresses and passwords were authentic, the NIH was the hardest hit by the breach with 9,938 credentials posted online. The CDC had 6,857 credentials leaked, while the list of WHO email addresses and passwords totalled 2,732.

The Gates Foundation and the Wuhan Institute of Virology lost 269 and 21 credentials respectively.

A spokesperson for the NIH said in a statement: “We are always working to ensure optimal cyber safety and security for NIH and take appropriate action to address threats or concerns."

Yvonne Eskenzi, founder of cybersecurity PR agency Eskenzi, told IT Pro that “it’s too early to say if these credentials are old or current”.

“It just highlights the constant and relentless attacks all companies are under but particularly right now the healthcare is seeing a barrage of attacks of ransomware and credential theft,” she said.

“The healthcare sector has the most valuable and sensitive data and we’ve learnt from our cybersecurity clients that the level of attacks has increased dramatically during the COVID-19 crisis, surpassing the financial sector who have always been the first port of call. This is a sickening and tragic development and shows that there are no depths to which the cybercriminals will stoop too.”

Last month, cyber criminals targeted hospitals across Europe in an effort to compromise their computer systems while healthcare workers deal with a dramatic influx of patients due to the coronavirus outbreak.

Sabina Weston

Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.

Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.