Australasian Leisure Management
Feb 2, 2024

Football Australia reveals data breach

Participants' private information has reportedly been exposed after a data breach at Football Australia.

The weakness in the governing body’s online security exposed a range of data - including players' personal details, contracts, and passports, as well as additional data about ticket purchase information, and detailed source code and scripts of Football Australia's digital infrastructure – to being leaked online.

According to independent cybersecurity research publication Cybernews, the Football Australia accidentally left plain-text digital ‘keys’, including ‘secret keys’, lingering in the publicly-accessible code of its sub-domain, meaning anybody could access it if they knew where to look.

These keys are understood to have supposedly provided the publication's researchers with access to 127 digital storage containers which contain data and private details from grassroots participants all the way through to national team players.

Cybernews say they contacted Football Australia about the data breach, and that the governing body fixed the issue before the researchers published their story.

They claim the most likely reason behind the data breach was human error, "as a developer likely inadvertently left a reference hidden in a script accessible to the public. Nevertheless, the mistake represents a critical data exposure incident".

On Wednesday afternoon, FA's centralised registration platform PlayFootball was taken offline for a few hours, returning "504 Error" messages when people tried to register for upcoming competitions. The platform went back online later that evening.

In a statement on Thursday, Football Australia said it was "aware of reports of a possible data breach and is investigating the matter as a priority.

"Football Australia takes the security of all its stakeholders seriously.

"We will keep our stakeholders updated as we establish more details."

Following reports on 7 News Sydney today (Saturday 3rd February), Football Australia released a further statement, correcting what it called “misreporting” on the matter.

The Football Australia statement advised that the 7 News Sydney “report contains several inaccuracies and was highly speculative, despite Football Australia providing the relevant facts to the reporter.

“Although we are aware of the inadvertent exposure of certain credentials on Football Australia's FIFA Connect System, it's crucial to clarify the nature of the inadvertent exposure. Contrary to the claims in the 7 News report, the exposed credentials did not provide access to information such as international player contracts, domestic participation registration data, or competition details.

“We emphasise that the suggestion that community registration platforms were at risk is misleading, as is the linking of betting and match manipulation. In any case, Football Australia acted swiftly and remedied that exposure within hours of becoming aware.”

FIFA Connect is an initiative by FIFA to assist member associations in systematically registering all stakeholders, including players, coaches and referees.

Related Articles

Grassroots partnership announced for Football Australia’s MiniRoos and Milo
Jan 30, 2024
Football Australia commences selection of additional clubs for new national second division
Jan 28, 2024
Life Saving Victoria advises of cyber attack
Dec 23, 2023
Nudgee Recreation Reserve reborn as new base for Football Queensland
Dec 10, 2023
New Auckland A-Leagues club names Terry McFlynn as Director of Football
Dec 3, 2023
Matildas and Socceroos drive Football Australia to 48% increase in revenue
Nov 23, 2023
Football Australia announces eight teams for new national second division
Nov 19, 2023
Football Australia and Nike unveil new 10-year partnership
Nov 18, 2023
Football Victoria owed almost $2 million by local clubs
Nov 17, 2023
Football Australia pay deal sees Matildas get parity with Socceroos
Nov 7, 2023
Football Australia rules out 2034 FIFA World Cup bid in boost for Saudi Arabia hopes
Oct 30, 2023
Western United to play A-League home games at Wyndham Regional Football Facility
Oct 19, 2023
Western Australian arts organisation targeted in data breach
Jul 25, 2022
Fitness and Lifestyle Group sign with Airlock Digital to protect against cyber attacks
Jul 1, 2021
Kate Palmer apologises for 'unauthorised access' following Sport Australia email hack
Dec 10, 2019
YMCA NSW locations impacted by ransomware attack
Aug 16, 2019
Ticketmaster Data breach alleged to be part of a wider fraud
Jul 10, 2018
Swimming Australia website under 'cyber attack' after Mack Horton's 'drug cheat' remarks
Aug 12, 2016
AIS helping protect athletes from cybercrime
Jul 10, 2016
PaySmart continues to set industry benchmark in data security
Mar 13, 2014
Australasian Leisure Management Magazine
Subscribe to the Magazine Today

Published since 1997 - Australasian Leisure Management Magazine is your go-to resource for sports, recreation, and tourism. Enjoy exclusive insights, expert analysis, and the latest trends.

Mailed to you six times a year, for an annual subscription from just $99.

New Issue
Australasian Leisure Management
Online Newsletter

Get business and operations news for $12 a month - plus headlines emailed twice a week. Covering aquatics, attractions, entertainment, events, fitness, parks, recreation, sport, tourism, and venues.