LIVE · cybersecurity feed
Live wire
breach

Privacy own-goal: World Cup blunder leaks Lionel Messi’s passport details

Argentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hackers, but by someone who failed to redact a document properly. document. It's a mistake that has been made many times in the past... Read mor

zeroday.news · 50d ago

Details from the passports of every player on Argentina's World Cup squad, including star player Lionel Messi, were inadvertently leaked to the public ahead of a recent match. The sensitive information was present on an official team sheet circulated before a friendly game against Iceland.

The security lapse occurred at Alabama's Jordan-Hare Stadium, where the team sheet was distributed without the passport numbers being properly obscured. This affected all 11 starting players as well as the substitutes. The incident took place before a match attended by approximately 88,000 spectators.

Under FIFA regulations, teams are required to submit passport numbers to referees about an hour before a match. This is to allow officials to verify player identities and ensure eligibility, preventing the use of fraudulently naturalized players. While this information is necessary for match officials, it is not intended for public or media distribution. Typically, a redacted version of the team sheet is provided to journalists.

In this instance, the standard procedure of redacting sensitive data was apparently overlooked. Passport numbers are considered valuable to criminals for identity theft, the creation of fraudulent travel documents, or for profiling individuals for potential targeting.

This incident echoes previous privacy breaches where sensitive information was not effectively hidden. For example, in January 2019, legal documents filed in federal court by lawyers for Paul Manafort appeared to have redactions, but the underlying text could be accessed by copying and pasting the document's content. This revealed that Manafort had allegedly shared polling data with an associate linked to Russian intelligence and had misled investigators.

More recently, in 2023, Sony provided a document during an antitrust hearing that contained confidential details about publisher profit margins, revenue figures for games like Call of Duty, and development costs. Some of this information, which Sony intended to keep private, became visible after being marked with a black Sharpie marker and then scanned. In December 2025, the U.S. Department of Justice released millions of files related to Jeffrey Epstein, where some information was superficially obscured by black boxes, but the underlying data remained accessible.

These events highlight a common issue: mistaking the appearance of redaction for actual redaction. Simply covering text with a black box in an electronic document does not guarantee that the information is inaccessible. The fundamental solution, regardless of whether one is an individual, a company, or involved in organizing major sporting events, is to rigorously verify that sensitive data has been permanently removed or rendered unreadable before releasing any document. Failure to do so can result in significant privacy violations and compromise the security of others.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in