The Asian Football Confederation (AFC) and six football clubs have reportedly suffered a significant data breach, exposing sensitive personal information. A threat actor, Ddarknotevil, has claimed responsibility for the attack, alleging that the compromised data includes full names, passport details, dates of birth, and nationalities of individuals associated with the AFC.
The hacker claimed that the attack occurred on March 25. The stolen database contains records of 69,508 players, 24,745 team officials, 81,827 coaches, and 3,200 referees, along with information on high-profile individuals.
The leaked details reportedly include AFC ID numbers, passport numbers, and other sensitive identification data.
The breach extends beyond the AFC, with the attacker also asserting they have accessed data from several high-profile football clubs, including Al-Sadd (Qatar), Al-Ahli (Saudi Arabia), Al-Ain (UAE), Al-Hilal (Saudi Arabia), Al-Nassr (Saudi Arabia), and Persepolis FC (Iran).
The hacker claims to have obtained full contracts, passports, and contact information of individuals associated with these clubs.
In the breach post, the hacker alleges that AFC ignored their attempts to establish contact and now offers the stolen database for sale, accepting cryptocurrency (XMR) as payment. They also emphasise that escrow is required for the transaction, warning potential buyers to be cautious of scammers.
If confirmed, this breach could be detrimental to the players, officials, and coaches. This information is quite valuable for scammers, other threat actors, or even other clubs.
Recently, a hacker named Blinkers claimed to have breached Cricadda, a platform associated with online gaming and betting in India and other countries. Other breaches include GrubHub, OpenAI, BC Jindal Group, OmniGPT, SkilloVilla, and CHC data, among others.
In India and Brazil, major government websites have faced data breaches recently. For instance, in January 2025, the Brazilian Finance Ministry faced a cyber attack exposing sensitive financial data.
In the News: Microsoft starts naming miscreants in its AI service abuse lawsuits