A security researcher found a flaw in FIFA’s online platforms that gave her access to several internal systems, including one that could have allowed her to take control of the television broadcast stream of every World Cup match.
The vulnerability, disclosed as the 2026 FIFA World Cup got underway on June 11 across 16 host cities in the US, Canada, and Mexico, raises serious questions about the digital infrastructure underpinning one of the most-watched events in human history. The tournament runs through July 19, meaning weeks of matches could theoretically have been compromised.
What the flaw actually exposed
The researcher reported that the vulnerability granted access to internal FIFA systems, not just surface-level data. The critical piece: a system connected to broadcast controls for World Cup matches.
FIFA has not publicly confirmed any impact from the vulnerability, nor has the organization detailed what remediation steps it has taken. The identity of the researcher has not been disclosed either.










