Football Australia exposed player passports and contracts through leaked AWS keys
- Organization
- Football Australia
- Exploit
- Human Error
- Industry
- Sports Governing Body
Football Australia, the national governing body for the sport, exposed a large volume of internal data after developers embedded Amazon Web Services access keys in plain text in the client-side code of its website. Researchers at Cybernews found the credentials and disclosed the problem publicly on February 1, 2024.
The keys unlocked 127 cloud storage buckets. One of them had been left open entirely, requiring no credentials at all, and held football players' passport scans and contracts. Other buckets contained ticket purchaser records, internal infrastructure details, and source code and scripts for the organization's digital systems. Researchers said the exposure covered personal identifiers and documents belonging to players and to people who had bought tickets, though the number of individuals involved was never established.
Analysis of the exposure indicated the keys had been present since around March 2022 and were never rotated, leaving them retrievable by anyone who viewed the page source for roughly 681 days.
Football Australia said it was aware of reports of a possible data breach and was investigating the matter as a priority. The exposed keys were removed after the organization was notified. There was no public evidence that anyone other than the researchers had retrieved the data, and no confirmed count of affected individuals had been released as of the reporting date.