When Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

📋 Key Takeaways
  • What happened?
  • The paper trail
  • A theme too good for criminals to resist
  • Who was doing the targeting?
  • The responders as critical infrastructure
8 min read · 1,417 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

What happened?

In late March 2020, as the world scrambled against a pandemic, Reuters reported that cyberattackers had set up a near-identical imitation of the World Health Organization’s internal email portal – a digital doppelganger built to harvest credentials from the very people fighting the crisis. Days earlier, roughly 450 active WHO email addresses and passwords, along with thousands of credentials from other pandemic responders, had been dumped online. The attacks were part of a surge: opportunistic criminals and suspected state-aligned actors alike pivoted their tooling to COVID-19 lures within days of the outbreak, calculating that fear, urgency, and overworked staff made the pandemic the best phishing theme money could not buy. Targeting the responders was the scandal – the organizations holding the worlds health response together were now the preys of both scam artists and intelligence services. This is the story of a crisis within the crisis.

Quick Answer: In March 2020, Reuters and WHO officials reported a near-identical malicious imitation of WHO’s internal email portal set up to steal credentials from staff and responders, alongside the online leak of around 450 active WHO email addresses and passwords plus thousands more from other pandemic-response organizations. The incidents exemplified a broad pandemic-themed attack surge – phishing, fake sites, and malicious apps – documented by WHO, FBI IC3, CISA, and NCSC throughout spring 2020, driving public warnings and hardening of health-sector portals.

The imitation-site technique deserves the emphasis it received. Cloning the ArcGIS-style dashboards, document libraries, and login pages lets an attacker inherit trust: a responder who types their real WHO credentials into a pixel-perfect replica hands over the keys willingly, no exploit needed. Reuters reporting described the malicious site as near-identical to the organizations internal email system, implying reconnaissance of the real portals design and, potentially, a watering-hole strategy aimed at the health community during its busiest hours. The credential dump compounded the exposure: 450 active address-password pairs represent 450 potential account takeovers of a global institution at its most overload point, and the inclusion of thousands more credentials from other responders sketched a supply chain of compromised crisis workers. WHO’s own cybersecurity chief publicly acknowledged the escalation, calling it part of a doubling of attacks on the organization.

The paper trail

Date Event
2020-03-13/17 WHO reports surge in scams imitating its domain; fake COVID-themed sites and emails spread globally
2020-03-20 FBI IC3 press release warns of COVID-19-themed phishing, fake cures and supplies, and malicious apps imitating dashboards
2020-03-23 CISA and UK NCSC joint alert on pandemic-related phishing and malware, urging verification and reporting of spoofed health sites
2020-03-24 Reuters reports near-identical malicious imitation of WHO’s internal email portal targeting staff, plus ~450 WHO credentials and thousands more from other responders leaked online
2020-04-onward WHO and partners harden portals, rotate credentials, publish dashboards tracking spoofed domains, and report sustained targeting through 2020
data-hmmnm-seam="2">

A theme too good for criminals to resist

What March 2020 proved at industrial scale is that lures track attention. Every phisher, BEC artist, and malware distributor repackaged existing tooling with COVID themes within weeks: fake cures, mask shortages, stimulus payments, temperature checks, remote-work policy updates, and dashboard apps carrying infostealers. Template kits with pandemic branding circulated in criminal forums openly. The responders community – hospitals, agencies, NGOs – absorbed a disproportionate share, both because their email volume exploded and because urgency degrades verification habits. Security vendors reported pandemic-themed phishing becoming the dominant lure category within the month. The lesson recurs in every disaster: the theme is free, the attention is guaranteed, and the only durable defense is verification behavior that survives adrenaline.

data-hmmnm-seam="3">

Who was doing the targeting?

Attribution split along motive lines. Criminal actors ran the volume operations: credential harvesting, fake shops, ransomware opportunistically hitting hospitals already at capacity. State-aligned operations ran the quieter lines: espionage against vaccine research, government crisis coordination, and public-health policy deliberations, documented in vendor and government reporting through 2020 (with multiple Western governments publicly attributing campaigns to familiar intelligence services later that year). The WHO-portal imitation sat at the ambiguous intersection – sophisticated enough for a patient operation, modular enough for a criminal upgrade. WHO’s public statements declined firm attribution, which is standard for an institution whose neutrality is operational infrastructure. For defenders, the practical takeaway did not depend on the flag: credential hygiene, MFA everywhere, verified communications channels, and portal hardening were the correct responses regardless of who profits from the breach.

data-hmmnm-seam="4">

The responders as critical infrastructure

March 2020 seeded a doctrine shift: public health became, formally, a critical infrastructure sector in defensive planning. The pandemic demonstrated that hospitals and health agencies satisfy every criterion: life-safety function, brittle IT under load, legacy systems, and now demonstrated hostile targeting at scale. Health-sector targeting did not pause after the crisis peaked; ransomware crews would prove through 2020-2021 that medical institutions remained premium targets (a French hospital ransomware case later that year, the Irish health service the next). The credential dumps and portal attacks of March were the opening moves of that campaign, and the policy world responded in kind: sector-specific guidance, information-sharing intensives, and law-enforcement coordination that treated hospital intrusion as public safety, not commerce. The pandemic taught that the threat model must include the attackers who show up precisely when the target is weakest.

  • Crisis theme is free attack budget: pandemic lures converted existing criminal tooling into top-performing campaigns within weeks; verification discipline is the only control that scales with adrenaline.
  • Imitation sites inherit trust: pixel-perfect login clones harvest real credentials without exploits; portal owners must monitor for lookalike domains and pre-emptively educate users.
  • Credentials are the real breach: 450 active WHO passwords dumped online represented 449 potential account takeovers of crisis operations; MFA and rapid rotation are existential, not optional.
  • Defend the responders: health and crisis-response institutions absorb disproportionate targeting exactly when capacity is lowest; sector-specific defense is public safety policy.

FAQ

How was WHO targeted in March 2020?

Multiple ways simultaneously: a near-identical imitation of its internal email portal was set up to harvest staff credentials; around 450 active WHO email addresses and passwords, plus thousands of credentials from other pandemic responders, were leaked online; and spoofed WHO domains and emails spoofing officials multiplied across the internet as part of the broader pandemic-themed surge.

Whose credentials were leaked?

Approximately 450 active WHO email addresses with passwords appeared online, alongside thousands more belonging to other organizations and individuals involved in the pandemic response. The dump’s breadth, spanning multiple responder organizations, suggested systematic harvesting rather than a single isolated compromise.

Was anyone attributed for the attacks?

WHO declined to attribute the portal imitation and credential leak publicly. Criminal actors were behind most pandemic-themed volume phishing, while government and vendor reporting through 2020 attributed quieter espionage against health research and policy deliberations to state-aligned services; the March incidents sat at the boundary between the two economies.

What did defenders recommend at the time?

Multi-factor authentication on all remote-access and email paths, credential rotation for exposed accounts, verification of domains and senders before interaction, reporting spoofed sites to takedown programs, and treating health-sector portals as high-value targets deserving proactive hardening – all reinforced by the FBI, CISA, and NCSC advisories of the period.

Did the attacks succeed in disrupting the pandemic response?

No single publicly confirmed disruption of WHO operations resulted from the March incidents, but the cumulative targeting forced response organizations to divert scarce security resources during peak crisis and set the pattern for sustained health-sector attacks through 2020 and beyond, including ransomware incidents that did disrupt hospital operations.

data-hmmnm-seam="5">

Legacy: attacking the ambulance

The March 2020 WHO incidents endure as the emblem of pandemic-era targeting: the moment attacking the responders became normalized business. The imitation portal remains the teaching example of trust-inheritance attacks – no exploit, just craftsmanship applied to a login page – and the credential dumps remain the argument for phishing-resistant authentication across entire sectors rather than executive suites. Policy inherited the incident as a pillar of health-sector security doctrine: information sharing between health institutions and agencies intensified, takedown infrastructure for spoofed domains expanded, and hospitals entered critical-infrastructure threat models permanently. The ethical line the events drew has held better than expected: even ransomware ecosystems subsequently developed (often violated) norms against hospital targeting, a boundary first articulated during this period. What March 2020 established for every future disaster is procedural: crisis institutions must assume targeted attacks as a predicate of crisis, with identity hardening, lookalike-domain monitoring, and responder training scaled before the emergency, not during it. The ambulance now drives with an escort; attackers learned there is no truce in a pandemic, and defenders wrote that lesson into the architecture of everything that came after.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.