The Argentine Football Association (AFA) is investigating a suspected compromise after attackers allegedly used credentials stolen from a software developer’s device infected with an infostealer in September 2025. The intrusion surfaced when mass emails were sent from legitimate AFA domains falsely claiming Argentina had “stolen” a World Cup win from Egypt, indicating unauthorized access to internal systems. Security researchers at Hudson Rock said the stolen credentials may have enabled broad administrative access across AFA assets, including databases, management portals, media infrastructure, and the competition system.
Data later advertised on cybercrime forums was said to include staff, club, and partner information, along with internal email addresses, phone numbers, user roles, registration timestamps, subdomain access listings, and some plaintext passwords. Hudson Rock also reported that weak password reuse across internal systems likely worsened the breach’s impact by allowing wider lateral access once the initial credentials were obtained. AFA acknowledged possible unauthorized access and said it is investigating the incident and implementing security measures.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The Argentine Football Association acknowledged possible unauthorized access to its systems and said it was investigating the incident while implementing security measures.
Following the apparent intrusion, posts on cybercrime forums advertised AFA data for sale, including staff, club, and partner information, internal email addresses, phone numbers, user roles, registration timestamps, subdomain access listings, and some plaintext passwords.
The suspected breach became visible after mass emails were sent from legitimate AFA domains claiming Argentina had stolen a World Cup win from Egypt, indicating unauthorized access to AFA infrastructure.
Hudson Rock said the suspected compromise chain began when an infostealer infected a software developer’s device tied to the Argentine Football Association, potentially exposing credentials later used to access AFA systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.