A threat actor allegedly leaked data from the Asian Football Confederation (AFC) and records tied to Al Nassr FC, claiming exposure of more than 150,000 player, coach, and member records on a cybercrime forum and the dark web. Reported samples included passport scans and numbers, contracts, verified email addresses, AFC registration files, AFC IDs, and detailed player information such as names, dates of birth, nationalities, club affiliations, match details, and venue data. The seller called it the "largest breach in football history" and invoked ShinyHunters, but Dataminr assessed that reference as likely an attempt to borrow the group’s reputation rather than evidence of direct affiliation.
Researchers warned that the combination of identity documents, contract data, and verified contact information could enable identity fraud, business email compromise, contract manipulation, and highly targeted social engineering against athletes, coaches, and officials. Dataminr also noted that some allegedly leaked documents included diplomatic passports, expanding the potential impact beyond sports operations to tournament logistics and broader national security concerns as AFC member nations prepare for the 2026 FIFA World Cup. At the time of reporting, the AFC had not publicly commented on the alleged compromise, while security experts urged organizations to review athlete-data storage, third-party access, financial verification workflows, and monitoring for suspicious communications.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
By April 29-30, 2026, multiple outlets reported the alleged breach publicly, describing it as potentially the largest breach in football history and noting sample records tied to AFC and Al Nassr FC. At the time of reporting, the Asian Football Confederation had not publicly commented on the incident.
Researchers reported that the alleged leak included passport scans and numbers, verified email addresses, contracts, AFC IDs, registration files, and detailed player and coach information. They warned the data could enable identity fraud, business email compromise, contract manipulation, and targeted social engineering against athletes, staff, and officials.
On April 27, 2026, a threat actor allegedly posted a leaked archive on a prominent cybercrime forum, claiming to have data from the Asian Football Confederation and Al Nassr FC affecting more than 150,000 player and coach records. The actor referenced ShinyHunters, though reporting assessed this as likely an attempt to borrow the group's reputation rather than evidence of direct affiliation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcelinkedin.com
Open sourceupguard.com
Open sourcetechradar.com
Open sourcedataminr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.