On 18 January 2022 the International Committee of the Red Cross disclosed a compromise affecting the personal data of more than 515,000 people. The data belonged to Restoring Family Links, the programme that reunites people separated by armed conflict, migration and disaster, and that traces people held in detention.
Reporting attributes entry to CVE-2021-40539, an authentication bypass leading to remote code execution in Zoho ManageEngine ADSelfService Plus. Post-exploitation is described as web shells, compromise of administrator accounts, lateral movement and exfiltration of registry hives and Active Directory files. The intruders were present for around 70 days before discovery. The ICRC characterised the actor as a nation state.
The Data Exists Because The People Are Hiding
Most registers in this corpus hold people who are findable anyway — customers, patients, employees. This one holds the opposite. A person on the Restoring Family Links list is frequently someone whose location is not widely known, sometimes deliberately: a detainee, a person who fled, a family that separated at a border.
The harm from publication is therefore not identity theft. It is being located. No remedy in the catalogue this desk keeps criticising — credit monitoring at 25-1031, document replacement at 22-0922 — has any bearing on that, and the corpus records at 22-1024 that when the harm is of this kind there is nothing to offer.
The Patch Existed
CVE-2021-40539 was not a zero-day at the time of the intrusion. It had been disclosed and fixed by the vendor months earlier, and had been the subject of federal advisories.
This is the category the corpus files at 23-0518 and 25-0719 — a known, fixed flaw in an internet-facing management product, exploited on the estates that had not applied it. The desk does not treat that as a moral failing; a humanitarian organisation is not a security company, and 70 days of undetected presence says as much about monitoring as about patching.
There Is No Second Red Cross
The corpus keeps returning to populations that did not choose the organisation holding their data — patients at 26-0721b, customers of a billing vendor at 26-0713. This is the sharpest version. A person seeking a missing relative across a conflict line has one organisation with the mandate and the access to do it.
That is a concentration created by neutrality itself, and it is not fixable by competition. The ICRC published the compromise, said what it did not know, and asked the attackers not to publish. Whether that is a security posture or a moral appeal is the open question of this file.
Built on the ICRC’s own statement and contemporaneous reporting of it. The 515,000 figure, the Restoring Family Links programme, the 18 January 2022 disclosure, the ~70-day dwell, and the identification of CVE-2021-40539 in Zoho ManageEngine ADSelfService Plus as the entry point are as stated and reported. The characterisation of the actor as a nation state is the ICRC’s, reported on its assessment; no state is named here and none was publicly named by the organisation. This desk has not seen forensic material. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.