I Could've Rickrolled the FIFA World Cup. All I Needed Was My ID

A security researcher discovered a critical vulnerability in FIFA's Agent Platform that allowed unauthorized access to the production streaming management panel for the 2026 World Cup. The flaw stemmed from a failure to validate user roles on the backend, despite client-side restrictions.
Why it matters
This highlights the severe risks of insecure authentication in large-scale event management systems and the importance of backend security validation.
They fixed it without ever responding to me. I had to call FIFA, MediaKind, HBS, CISA, and the FBI at 3am Tokyo time just to get someone to listen. This is that story.
The article is a technical account of a security vulnerability and does not exhibit political or social bias.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in