A cache of nearly 25,000 email addresses and passwords allegedly belonging to the World Health Organization (WHO), National Institutes of Health (NIH), Wuhan Institute of Virology, Bill Gates Foundation and several other groups involved with the coronavirus pandemic response were dumped on 4chan before appearing on several other websites, according to the SITE Intelligence Group.
The report by SITE, based in Bethesda, Md., said the largest group of alleged emails and passwords was from the NIH, with 9,938 found on lists posted online. The Centers for Disease Control and Prevention had the second-highest number, with 6,857. The World Bank had 5,120. The list of WHO addresses and passwords totaled 2,732. –Washington Post
WHO chief information officer Bernardo Mariano told Bloomberg that the organization wasn’t hacked, and that the data was possibly obtained through prior data breaches.
“The employees may have used their work email address to register an account for a particular website, and then that website has been hacked, leaking their password.”
According to Mariano, 400 of the credentials were still active – and he claims that none of the passwords were used to access sensitive information due to the organization’s two-factor authentication system. 4chan users, on the other hand, said that they were able to use the passwords to gain access to a WHO website called “Extranet,” according to Bloomberg.