An egregious access control vulnerability in FIFA's Microsoft Entra environment allowed an ethical hacker to gain direct control over global World Cup television streams, match management systems, and more. On June 14, a hacker named "BobDaHacker" discovered that the international soccer governing body's entire online infrastructure was thinly guarded from any random hacker on the Internet. With an easily crafted fake account, they managed to reach all of the systems used to run the World Cup. If BobDaHacker had worse intentions, they could have easily blacked out the tournament for global audiences or even replaced everyone's television streams with Rick Astley. Instead, they invested unusual effort in responsibly reporting the issue. Dark Reading attempted but ultimately failed to reach FIFA for comment and clarification on this story. Anyone can file to become a football agent, whether you're a louse exploiting some South American wunderkind or Adrien Rabiot's mother. All you have to do is submit your ID and verify your email address on the FIFA Agent Platform. If you freely choose to do that, FIFA will create an account for you in its Microsoft Entra tenant. Evidently, it's the same tenant that supports all of FIFA's internal systems. BobDaHacker registered as an agent, then attempted to exploit their new account to reach FIFA's core data platform. The response from the server was reassuring: They were denied, thanks to a lack of privileges. Except that response was super...
FIFA Bug Exposes World Cup Streams to Remote Takeover
Dark Reading
·Nate Nelson
·Published Jun 18, 2026
·Updated
Affected Software
8 affected components
Microsoft Entra
FIFA Agent Platform
FIFA Core Data Platform
FIFA Streaming Management Platform (Live Production Hub)
FIFA Match Management Platform
FIFA Commentary Information System
FIFA Gametime Analytics Platform
FIFA Developer Environment
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a significant access control vulnerability in FIFA's Microsoft Entra environment that allowed a hacker to access World Cup streams.
2
What security implications are discussed in the article?
The article highlights the risk of remote takeover of World Cup television streams and match management systems due to the vulnerability.
3
Who discovered the vulnerability mentioned in the article?
The vulnerability was discovered by an ethical hacker known as 'BobDaHacker'.
4
What products or software are affected by this security vulnerability?
The affected software includes various FIFA platforms such as Microsoft Entra, FIFA Streaming Management Platform, and FIFA Match Management Platform.
5
When was the vulnerability published and when was it exploited?
The vulnerability was published on June 18, 2026, and it was exploited shortly thereafter, as indicated in the KEV listing.