FIFA World Cup API Flaw Allows Unauthorized Broadcast Control

FIFA World Cup API Flaw Allows Unauthorized Broadcast Control

First seen 16 Jun 2026, 23:44 UTC TechcrunchFeeds.FeedburnerItnews.AuDarkreadingwww.theguardian.com+2 87% similarity 64.5

Article Content

Browse articles
ThreatCluster

A security researcher, known as BobDaHacker, exploited a vulnerability in FIFA's backend API by registering as a player agent, which granted her unauthorized access to internal systems. This flaw allowed full control over the TV streams for all World Cup games, enabling potential manipulation of broadcast content. The researcher demonstrated that an attacker could hijack all cameras simultaneously or alter on-screen content globally. BobDaHacker reported the vulnerability on June 16, 2026, and FIFA addressed the issue within hours but did not publicly acknowledge the report. The incident raises significant concerns about the security of major sporting events and the integrity of live broadcasts.

Key Points: • A critical API flaw in FIFA's systems allowed unauthorized access to broadcast controls. • The researcher demonstrated the ability to manipulate TV streams for all World Cup games. • FIFA fixed the vulnerability within hours of the report but did not acknowledge the researcher.

ThreatCluster AI How this analysis works

Timeline

2026-06-16
Vulnerability reported by researcher
BobDaHacker reported a flaw in FIFA's backend API that allowed unauthorized access to internal systems controlling broadcasts.
Techcrunch
2026-06-16
FIFA addresses the vulnerability
FIFA fixed the API flaw within hours of the report but did not publicly acknowledge the researcher's findings.
Techcrunch

Community

Browse all →

Tracked Entities in This Story