FIFA Bug Opens World Cup Broadcasts to Remote Takeover

TOPICS
MORE LIKE THIS

This week’s TL;DR covers two stories that highlight just how broad the attack surface has become. One was a near-miss for FIFA, the other a picture of how cybercrime is accelerating.

An ethical hacker going by “BobDaHacker” discovered that FIFA’s entire online infrastructure was accessible to anyone with a basic internet account and a willingness to look past a client-side “access denied” message.

The vulnerability stemmed from a fundamental access control failure in FIFA’s Microsoft Entra environment. Anyone can register as a football agent on the FIFA Agent Platform by submitting an ID and verifying an email address. FIFA creates that account within the same Entra tenant that supports its internal systems. When BobDaHacker registered as an agent and attempted to probe deeper, the frontend dutifully displayed a denial, but the backend API ignored it entirely, serving up full access to whoever asked.

That access turned out to be very broad. BobDaHacker was able to reach FIFA’s live streaming management platform, complete with full playback controls! A malicious actor could have blacked out matches mid-game or replaced live coverage with anything they chose, across every TV network worldwide simultaneously. Beyond broadcasting, the same unprivileged agent account also unlocked FIFA’s match management platform. As well as its commentary information system, its gametime analytics platform, and a developer environment containing files related to revenues and player transfers.

Making matters worse, FIFA has no security.txt file, no vulnerability disclosure policy, no bug bounty programme, and apparently no direct route for a researcher to report a finding. BobDaHacker ultimately had to call CISA and the FBI to get the issue escalated. CISA is the federal lead for cybersecurity at the 2026 World Cup. The vulnerability appeared to be resolved the following day.

FIFA Security Failure – TL;DR

An ethical hacker gained full control over FIFA’s World Cup broadcasting infrastructure, including the ability to replace live match coverage on every TV network worldwide, simply by registering as a football agent and ignoring a client-side access denied message. The backend API had no server-side enforcement whatsoever. The absence of a vulnerability disclosure channel forced the researcher to involve CISA and the FBI to get the issue resolved.

INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report paints a picture of escalating cybercrime. Heavily driven by rapid digitalization, uneven cybersecurity maturity, and the growing involvement of organized criminal networks. Over half of INTERPOL member countries in the region reported that cybercrime now accounts for at least 30% of all nationally recorded crimes.

Phishing leads the field as the most widespread and financially damaging threat, with a third of countries reporting more than 10,000 cases between January 2024 and March 2025. Residents in the region clicked on phishing links at nearly double the global average rate. Cybercriminals launched more than 135,000 ransomware attacks in 2024 alone, targeting real estate, manufacturing, and financial services more heavily than any other sectors. DDoS attacks surged 92% year-on-year, while system intrusions accounted for around 80% of all data breaches.

AI and deepfake technology are adding a new layer of sophistication to existing threats. Organized crime syndicates operating out of Myanmar, Cambodia, and Laos have been deploying AI-generated scams, tricking victims into fraudulent investments. Cybercriminal groups are operating at an industrial scale, in some cases using forced labor to staff scam centers, and have driven an estimated $37 billion in cybercrime losses across the region. Infostealers such as RedLine, Lumma, and LokiBot remain deeply embedded in the threat landscape.

INTERPOL says law enforcement agencies across the region are stepping up joint operations, information sharing, and training in response, but notes that strengthening cyber resilience across the board remains essential as digital adoption continues to outpace security maturity.

INTERPOL Asia-Pacific Report – TL;DR

INTERPOL’s latest regional threat assessment confirms a dramatic rise in cybercrime across Asia and the South Pacific. Phishing, ransomware, DDoS, and AI-driven scams all increasing sharply. Criminal organizations are now running fraud on an industrial scale, fuelling losses estimated at $37 billion.

From a World Cup nearly hijacked by a basic API flaw to a continent-wide surge in AI-assisted cybercrime. Both show that attackers are finding gaps everywhere. No organization is too big, too public, or too scrutinized to be caught out by a fundamental security failure. ThinScale specializes in securing the endpoint, often the first and last line of defense. Get in touch to find out how we can help protect your environment.

Ready to see it in action?