NewsBite

Football Australia data breach affects ‘every customer or fan’: how your details could be exposed

Human error is believed to have caused the mass data breach of a cache of sensitive player information as well as the details of ‘every customer and fan’ of Football Australia.

Football Australia – which has been riding high on the Matildas making the World Cup semi-finals last year – has launched an investigation into the mass leak, saying it ‘takes the security of all its stakeholders seriously’. Picture: Getty Images
Football Australia – which has been riding high on the Matildas making the World Cup semi-finals last year – has launched an investigation into the mass leak, saying it ‘takes the security of all its stakeholders seriously’. Picture: Getty Images

Elite Australian soccer players and their fans have had a cache of personal information – including contracts, passports and ticket purchase details – leaked online in the nation’s latest data breach.

Football Australia – which has been riding high on the Matildas making the World Cup semi-­finals last year – has launched an investigation into the mass leak, saying in a three-sentence statement that it “takes the security of all its stakeholders seriously”.

Independent cybersecurity research site Cybernews released details of the break, which involved up to 127 buckets of data, including ticket buyers’ personal information, players’ contracts and documents.

Cybernews researchers said they could not quantify how many people were caught up in the data leak but believed that “every customer or fan of Australian football was affected”.

According to FA’s latest nat­ional participation report, the code attracted 1.53 million players across its programs.

The release of such sensitive data exposes players and fans to potential identity theft and other financial crime, with organised crime gangs targeting a raft of Australian companies in the past 18 months, given how lucrative such leaks can be.

FA was yet to confirm details of the breach, which Cybernews reported as being the result of “human error”.

“Football Australia is aware of reports of a possible data breach and is investigating the matter as a priority,” the organisation said.

“Football Australia takes the security of all its stakeholders seriously. We will keep our stakeholders updated as we establish more details.”

A Cybernews research team said FA had left plain-text Amazon Web Services keys – including secret keys – hardcoded into the HTML page of its subdomain.

“While we cannot confirm the total number of affected individuals, as it would require downloading the entire dataset, contradicting our responsible disclosure policies, we estimate every customer or fan of Australian football was affected,” the researchers said.

“The exposed data, including contracts and documents of football players, poses a severe threat as attackers could exploit this for identity theft, fraud, or even blackmail, emphasising the urgent need for improved security practices and measures to safeguard sensitive data.”

Cybernews said the cause was most likely human error, with a developer accidentally leaving a reference hidden in code accessible by the public.

Jared Lynch
Jared LynchTechnology Editor

Jared Lynch is The Australian’s Technology Editor, with a career spanning two decades. Jared is based in Melbourne and has extensive experience in markets, start-ups, media and corporate affairs. His work has gained recognition as a finalist in the Walkley and Quill awards. Previously, he worked at The Australian Financial Review, The Sydney Morning Herald and The Age.

Add your comment to this story

To join the conversation, please Don't have an account? Register

Join the conversation, you are commenting as Logout

Original URL: https://www.theaustralian.com.au/sport/football/football-australia-data-breach-affects-every-customer-or-fan-how-your-details-could-be-exposed/news-story/1d08eed7b041e29535b4ef825e62ef90