A security researcher discovered a critical flaw in FIFA’s internal systems that could have allowed anyone with a registered account to take control of the TV broadcast feed for World Cup matches. The researcher, who goes by the handle BobDaHacker, said she simply registered as a player agent on FIFA’s official agent registration platform. Then, due to having that account and a flaw in FIFA’s backend API — which didn’t verify whether a user actually had the proper authorization — she was able to access several internal FIFA platforms.
This included the system that allows broadcasters to control what gets displayed on televisions around the world, as well as what appears on commentators’ screens as they call the match. The vulnerability meant an attacker could manipulate camera feeds, overlay graphics, or even replace the broadcast entirely.
‘A single attacker could hijack every camera simultaneously. An attacker could have rickrolled the entire FIFA World Cup,’ BobDaHacker wrote in a blog post published Tuesday. The API flaw essentially meant that once authenticated as a player agent — a role that should have very limited system access — the backend treated the user as authorized for internal broadcast management systems.
BobDaHacker reported the flaw on Tuesday evening Japan time, and FIFA fixed the issue within a few hours, without ever acknowledging the researcher’s report. FIFA did not immediately respond to requests for comment.
The vulnerability highlights ongoing concerns about the security of large-scale sporting events, where complex integrations between multiple systems can create unexpected access paths. With the World Cup being the most-watched sporting event globally, the potential impact of such a flaw cannot be overstated. Researchers recommend that organizations implement proper role-based access controls and conduct thorough API security audits, especially for systems connected to live broadcast infrastructure.


