Details from the passports of every player on Argentina's World Cup squad, including star player Lionel Messi, were inadvertently leaked to the public ahead of a recent match. The sensitive information was present on an official team sheet circulated before a friendly game against Iceland.
The security lapse occurred at Alabama's Jordan-Hare Stadium, where the team sheet was distributed without the passport numbers being properly obscured. This affected all 11 starting players as well as the substitutes. The incident took place before a match attended by approximately 88,000 spectators.
Under FIFA regulations, teams are required to submit passport numbers to referees about an hour before a match. This is to allow officials to verify player identities and ensure eligibility, preventing the use of fraudulently naturalized players. While this information is necessary for match officials, it is not intended for public or media distribution. Typically, a redacted version of the team sheet is provided to journalists.
In this instance, the standard procedure of redacting sensitive data was apparently overlooked. Passport numbers are considered valuable to criminals for identity theft, the creation of fraudulent travel documents, or for profiling individuals for potential targeting.
This incident echoes previous privacy breaches where sensitive information was not effectively hidden. For example, in January 2019, legal documents filed in federal court by lawyers for Paul Manafort appeared to have redactions, but the underlying text could be accessed by copying and pasting the document's content. This revealed that Manafort had allegedly shared polling data with an associate linked to Russian intelligence and had misled investigators.
More recently, in 2023, Sony provided a document during an antitrust hearing that contained confidential details about publisher profit margins, revenue figures for games like Call of Duty, and development costs. Some of this information, which Sony intended to keep private, became visible after being marked with a black Sharpie marker and then scanned. In December 2025, the U.S. Department of Justice released millions of files related to Jeffrey Epstein, where some information was superficially obscured by black boxes, but the underlying data remained accessible.
These events highlight a common issue: mistaking the appearance of redaction for actual redaction. Simply covering text with a black box in an electronic document does not guarantee that the information is inaccessible. The fundamental solution, regardless of whether one is an individual, a company, or involved in organizing major sporting events, is to rigorously verify that sensitive data has been permanently removed or rendered unreadable before releasing any document. Failure to do so can result in significant privacy violations and compromise the security of others.






