Hackers leak credentials of WHO and Gates Foundation employees

Cyber criminals posted almost 25,000 email addresses and passwords to 4chan and Pastebin

Almost 25,000 email addresses and passwords allegedly belonging to employees of leading health organisations such as the World Health Organisation (WHO) and the US National Institutes of Health (NIH) have been leaked online in what is being described as a “harassment campaign”.

The news comes as WHO reported that it has been forced to double its security resources due to a significant increase in cyber attacks on the organisation since mid-March when the coronavirus moved up to pandemic status.

Advertisement - Article continues below

Director of SITE Intelligence Group Rita Katz told the Washington Post that “Neo-Nazis and white supremacists capitalized on the lists and published them aggressively across their venues (...) calling for a harassment campaign while sharing conspiracy theories about the coronavirus pandemic”.

Other victims of the breach include the Centers for Disease Control and Prevention (CDC), the World Bank, the Gates Foundation and the Wuhan Institute of Virology, who all had their credentials posted to sites such as 4chan and Pastebin.

According to SITE, which was unable to verify whether the email addresses and passwords were authentic, the NIH was the hardest hit by the breach with 9,938 credentials posted online. The CDC had 6,857 credentials leaked, while the list of WHO email addresses and passwords totalled 2,732.

Advertisement - Article continues below

The Gates Foundation and the Wuhan Institute of Virology lost 269 and 21 credentials respectively.

A spokesperson for the NIH said in a statement: “We are always working to ensure optimal cyber safety and security for NIH and take appropriate action to address threats or concerns."

Advertisement - Article continues below

Yvonne Eskenzi, founder of cybersecurity PR agency Eskenzi, told IT Pro that “it’s too early to say if these credentials are old or current”.

“It just highlights the constant and relentless attacks all companies are under but particularly right now the healthcare is seeing a barrage of attacks of ransomware and credential theft,” she said.

“The healthcare sector has the most valuable and sensitive data and we’ve learnt from our cybersecurity clients that the level of attacks has increased dramatically during the COVID-19 crisis, surpassing the financial sector who have always been the first port of call. This is a sickening and tragic development and shows that there are no depths to which the cybercriminals will stoop too.”

Last month, cyber criminals targeted hospitals across Europe in an effort to compromise their computer systems while healthcare workers deal with a dramatic influx of patients due to the coronavirus outbreak.

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now



UK delays rollout of NHS contact-tracing app

19 May 2020
data protection

Digital activists sound the alarm over UK's 'coronavirus datastore' plans

18 May 2020

These are the companies offering free software during the coronavirus crisis

15 May 2020
flexible working

The IT Pro Podcast: Staying sane while working from home

15 May 2020

Most Popular


The top ten password-cracking techniques used by hackers

5 May 2020

Nokia breaks 5G record with speeds nearing 5Gbps

20 May 2020
cloud computing

Microsoft launches public cloud service for health care

21 May 2020