Desk live·
ForensicPost
Nation-state/Humanitarian/File 22-0118

The Register of People Trying to Find Their Families

Attackers held the ICRC’s network for 70 days through a Zoho vulnerability patched months earlier. The data covered 515,000 people the organisation describes as vulnerable — separated by conflict, migration, detention or disaster.

Constructed geometry · not a chart of case data
JurisdictionSwitzerlandGenevathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetInternational Committee of the Red Cross
ActorUnattributed
S. Rosler12 min readConfidence: high3 sources reviewed

On 18 January 2022 the International Committee of the Red Cross disclosed a compromise affecting the personal data of more than 515,000 people. The data belonged to Restoring Family Links, the programme that reunites people separated by armed conflict, migration and disaster, and that traces people held in detention.

Reporting attributes entry to CVE-2021-40539, an authentication bypass leading to remote code execution in Zoho ManageEngine ADSelfService Plus. Post-exploitation is described as web shells, compromise of administrator accounts, lateral movement and exfiltration of registry hives and Active Directory files. The intruders were present for around 70 days before discovery. The ICRC characterised the actor as a nation state.

The Data Exists Because The People Are Hiding

Most registers in this corpus hold people who are findable anyway — customers, patients, employees. This one holds the opposite. A person on the Restoring Family Links list is frequently someone whose location is not widely known, sometimes deliberately: a detainee, a person who fled, a family that separated at a border.

The harm from publication is therefore not identity theft. It is being located. No remedy in the catalogue this desk keeps criticising — credit monitoring at 25-1031, document replacement at 22-0922 — has any bearing on that, and the corpus records at 22-1024 that when the harm is of this kind there is nothing to offer.

The Patch Existed

CVE-2021-40539 was not a zero-day at the time of the intrusion. It had been disclosed and fixed by the vendor months earlier, and had been the subject of federal advisories.

This is the category the corpus files at 23-0518 and 25-0719 — a known, fixed flaw in an internet-facing management product, exploited on the estates that had not applied it. The desk does not treat that as a moral failing; a humanitarian organisation is not a security company, and 70 days of undetected presence says as much about monitoring as about patching.

There Is No Second Red Cross

The corpus keeps returning to populations that did not choose the organisation holding their data — patients at 26-0721b, customers of a billing vendor at 26-0713. This is the sharpest version. A person seeking a missing relative across a conflict line has one organisation with the mandate and the access to do it.

That is a concentration created by neutrality itself, and it is not fixable by competition. The ICRC published the compromise, said what it did not know, and asked the attackers not to publish. Whether that is a security posture or a moral appeal is the open question of this file.

How we reported this

Built on the ICRC’s own statement and contemporaneous reporting of it. The 515,000 figure, the Restoring Family Links programme, the 18 January 2022 disclosure, the ~70-day dwell, and the identification of CVE-2021-40539 in Zoho ManageEngine ADSelfService Plus as the entry point are as stated and reported. The characterisation of the actor as a nation state is the ICRC’s, reported on its assessment; no state is named here and none was publicly named by the organisation. This desk has not seen forensic material. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Sophisticated cyber-attack targets Red Cross Red Crescent data on 500,000 peopleICRC
  2. Red Cross blames hack on Zoho vulnerability, suspects APT attackThe Record
  3. Red Cross cyber attack the work of nation-state actorsComputer Weekly
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary