A security researcher known as BobDaHacker discovered a major API vulnerability in FIFA’s internal systems on Tuesday, which could have allowed any user to hijack and modify the live television broadcast of any World Cup match.
How the FIFA API Vulnerability Was Exploited
The researcher explained that the exploit required nothing more than registering as a player agent on FIFA’s official registration platform. By exploiting a critical flaw in FIFA’s back-end API—which failed to verify if the account possessed the necessary authorisation—she successfully gained entry to several of the organisation’s restricted internal platforms.
Broadcaster and Commentator Screens Compromised
This unauthorised access granted her control over the exact systems that television broadcasters use to manage global feeds. Furthermore, the vulnerability exposed the screens used by live commentators to narrate the matches in real time.
“A single attacker could hijack every camera simultaneously. An attacker could have rickrolled the entire FIFA World Cup,” BobDaHacker wrote in a blog post published on Tuesday.
FIFA’s Silent Fix and Response
After discovering the vulnerability, BobDaHacker reported the issue on Tuesday evening (Japan time). Although FIFA resolved the security loophole just a few hours later, the sports governing body did so silently, without acknowledging the researcher’s contribution or report.
FIFA did not immediately respond to a request for comment regarding the security incident.
