Select Page

Incident: Football Australia data breach reportedly exposes contracts, passports, and ticket information | ABC News Australia

Incident: Football Australia data breach reportedly exposes contracts, passports, and ticket information | ABC News Australia

Australian Football Breach, 1 February 2024

Football Australia data breach reportedly exposes contracts, passports, and ticket information

Plain-text digital “keys” in the publicly accessible code, access to 127 digital storage containers

Company Statement: Football Australia is aware of reports of a possible data breach and is investigating the matter as a priority | 1st Feb 2024
Source: Football Australia data breach reportedly exposes contracts, passports, and ticket information | ABC News Australia

View more incidents relating to Sporting and Recreation sector.

YouTube player

 

Millions of football participants across Australia have potentially had their personal information leaked online after a security flaw was identified in Football Australia’s (FA) digital infrastructure.

The national governing body accidentally left plain-text digital “keys”, including “secret keys”, lingering in the publicly-accessible code of its sub-domain, meaning anybody could access it if they knew where to look.

These keys supposedly provided the publication’s researchers with access to 127 digital storage containers which contain data and private details from grassroots participants all the way through to national team players.

It is claim that the various buckets of data included players’ personal details, contracts, and passports, as well as additional data about ticket purchase information, and detailed source code and scripts of FA’s digital infrastructure.

Football Australia Statement
 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More Australian News

Weekly Australian News and Monthly Incident Review Emails

No advertisements, marketing, sales, or unsolicited emails. Your email address is ONLY used to send the publications listed above.

* indicates required


Shares
Share This

Discover more from Australian Information Security Awareness and Advisory

Subscribe now to keep reading and get access to the full archive.

Continue reading