Skip to content
FIFA World Cup API Flaw Allows Unauthorized Broadcast Control

FIFA World Cup API Flaw Allows Unauthorized Broadcast Control

First seen 16 Jun 2026, 23:44 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 23:15 UTC
  • A critical API flaw in FIFA's systems allowed unauthorized access to broadcast controls.
  • The researcher demonstrated the ability to manipulate TV streams for all World Cup games.
  • FIFA fixed the vulnerability within hours of the report but did not acknowledge the researcher.

A security researcher, known as BobDaHacker, exploited a vulnerability in FIFA's backend API by registering as a player agent, which granted her unauthorized access to internal systems. This flaw allowed full control over the TV streams for all World Cup games, enabling potential manipulation of broadcast content. The researcher demonstrated that an attacker could hijack all cameras simultaneously or alter on-screen content globally. BobDaHacker reported the vulnerability on June 16, 2026, and FIFA addressed the issue within hours but did not publicly acknowledge the report. The incident raises significant concerns about the security of major sporting events and the integrity of live broadcasts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-16
Vulnerability reported by researcher
BobDaHacker reported a flaw in FIFA's backend API that allowed unauthorized access to internal systems controlling broadcasts.
Techcrunch
2026-06-16
FIFA addresses the vulnerability
FIFA fixed the API flaw within hours of the report but did not publicly acknowledge the researcher's findings.
Techcrunch

More articles in this cluster (7)

Following this threat?

Track FIFA in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed