Bug in FIFA World Cup internal system gave anyone ability to modify TV stream

Published: (June 16, 2026 at 02:13 PM EDT)
2 min read
Source: TechCrunch

Source: TechCrunch

In Brief

Posted:

11:13 AM PDT · June 16, 2026

Cameramen TV during the FIFA World Cup 2026 Group C match between Brazil and Morocco at New York New Jersey Stadium on June 13, 2026 in East Rutherford, New Jersey.**Image Credits:**Image Photo Agency / Getty Images

										![Lorenzo Franceschi-Bicchierai](https://techcrunch.com/wp-content/uploads/2025/07/Lorenzo-headshot-2023-cropped.jpeg)
								
				

	

A security researcher said she was able to access several internal FIFA platforms due to a simple security flaw, which allowed her to watch and have full control of the TV stream of every World Cup game.

The researcher, who goes by BobDaHacker, said she simply registered as a player agent on FIFA’s official agent registration platform. Then, thanks to having that account and a flaw in FIFA’s back-end API, which didn’t check if a user actually had the proper authorization, she was able to access several internal FIFA platforms.

This included the system that allows broadcasters to control what gets displayed on people’s TVs across the world, and what gets displayed on commentators’ screens as they narrate the match, per the researcher.

“A single attacker could hijack every camera simultaneously. An attacker could have rickrolled the entire FIFA World Cup,” BobDaHacker wrote in a blog post published on Tuesday.

BobDaHacker reported the flaw on Tuesday night Japan time, and FIFA fixed the issue a few hours later, without ever acknowledging the researcher’s report.

FIFA did not immediately respond to TechCrunch’s request for comment.

Topics

Subscribe for the industry’s biggest tech news

Latest in Security

0 views
Back to Blog

Related posts

Read more »