Last updated 1 month ago
The Argentina national football team, representing the Argentina Government, suffered a data exposure incident prior to the 2022 FIFA World Cup. The breach was publicly disclosed in November 2022 after a document containing the passport numbers of the entire squad was leaked. The exact discovery date is not stated, and the number of records affected is not specified, but the exposure involved the entire 26-player roster.
The incident was not caused by a malicious external actor but by a failure to properly redact a document before its release. The attack vector is classified as a misconfiguration, as the document was inadvertently published with sensitive data visible. The exposed data type is passport numbers, which are considered personally identifiable information (PII) and could be used for identity theft or fraud. No threat actor was involved, and no CVEs or MITRE ATT&CK techniques are applicable.
No post-incident developments such as regulatory actions, litigation, or remediation milestones are mentioned in the article.
Improper redaction of a document containing passport numbers
This incident underscores the critical need for robust data redaction processes and automated validation checks before publishing any documents containing PII. The Argentina Government should implement mandatory redaction training for all personnel handling sensitive data and deploy tools that automatically detect and flag unredacted PII in documents prior to release.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector