Argentine Football Association (AFA) Breached via Year-Old Infostealer Credential Compromise — "All Egyptian Cyber Warriors"
Argentine Football Association (AFA) Breached via Year-Old (TL-2026-1265), also tracked as World Cup Grudge AFA Hack, is a high-severity data breach, first published 2026-07-13. It is attributed to All Egyptian Cyber Warriors with medium confidence, affects Argentine Football Association (AFA) afasistemas.com.ar, maps to 15 MITRE ATT&CK techniques (T1016, T1078, T1087), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-1265
- Threat ID
- TL-2026-1265
- Also known as
- World Cup Grudge AFA Hack, SYSTEM HACKED: UNFAIR DECISION
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- All Egyptian Cyber Warriors
- Attribution confidence
- MEDIUM
- Motivation
- HACKTIVISM
- Target sectors
- sports, government administration, news - media
- Target regions
- 005 - South America, argentina, North Africa, egypt
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Argentine Football Association (AFA) Breached via Year-Old
Malware and tooling: Unspecified infostealer
A hacktivist group calling itself "All Egyptian Cyber Warriors" gained administrative access to Argentine Football Association (AFA) systems using credentials stolen nearly a year earlier by an infostealer infection on a long-tenured AFA software developer's device, then sent mass emails from legitimate AFA domains protesting a disputed World Cup referee decision and advertised stolen AFA data on cybercrime forums.
How Argentine Football Association (AFA) Breached via Year-Old works
On 2025-09-08 an infostealer infection was detected on the personal or work device of a long-tenured Argentine Football Association (AFA) software developer; the compromised device and its harvested credentials were logged into Hudson Rock's infostealer victim/Cavalier database on 2025-09-09. The credentials sat dormant and unmitigated for roughly eleven months. On or around 2026-07-10/2026-07-11, following Argentina's controversial 3-2 World Cup Round-of-16 victory over Egypt (a match marred by a VAR-overturned Egyptian goal and disputed refereeing by François Letexier), a threat actor group identifying itself as "All Egyptian Cyber Warriors" leveraged the stale stealer-log credentials — reused, weak, and easily guessable across multiple internal systems — to obtain what AFA and researchers described as 'profound administrative control' over AFA infrastructure. Confirmed access included phpMyAdmin database-management panels, root-level access to AFA databases, the AFA training headquarters management portal, the AFA media portal, the competition management system, and the AFA management/admin portal hosted at afasistemas.com.ar. Using this access, the attackers sent mass emails from a legitimate, institutional AFA email account to journalists and other recipients worldwide with the subject line 'SYSTEM HACKED: UNFAIR DECISION,' opening with 'the robbery will not go unnoticed' and warning 'If there is no justice on the pitch, do not expect peace in your networks.' The emails characterized the Argentina-Egypt match outcome as the product of corrupt officiating. AFA publicly acknowledged on 2026-07-11 that 'there is a possibility that our account has been subject to unauthorized access' and stated the messages were 'neither generated nor authorised' by its staff, engaging IT personnel to investigate and cautioning recipients to disregard any follow-on messages containing links, attachments, or information requests. Data reportedly exfiltrated and later advertised for sale on cybercrime forums includes internal staff and external partner email addresses and phone numbers, user roles and account registration timestamps, access listings across AFA subdomains, and a large password set (the majority stored as hashes, with a smaller portion recovered/stored in plaintext). Hudson Rock, which surfaced and published the infostealer-to-breach linkage on 2026-07-13, characterized the incident as illustrating 'how devastating a single, unmitigated infostealer infection can be' and described the year-long dormant credential exposure as a 'ticking time bomb.' No CVE or software vulnerability underlies this incident; the root cause is pure credential theft via commodity infostealer malware combined with weak password hygiene and password reuse across internal systems, illustrating a now-recurring initial-access pattern (stealer-log credential monetization/reuse leading to high-privilege organizational compromise) independent of any patchable flaw.
MITRE ATT&CK techniques used in TL-2026-1265
Discovery
T1016 System Network Configuration Discovery; T1087 Account Discovery
Initial Access
Command and Control
Credential Access
T1110 Brute Force; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Collection
T1114 Email Collection; T1213 Data from Information Repositories
Impact
T1491 Defacement; T1657 Financial Theft
Lateral Movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
Affected products and versions in Argentine Football Association (AFA) Breached via Year-Old
- Argentine Football Association (AFA) — afasistemas.com.ar admin/management portal
Vulnerable versions: production instance, 2025-09 through 2026-07 - Argentine Football Association (AFA) — phpMyAdmin database management panel
Vulnerable versions: production instance - Argentine Football Association (AFA) — Training headquarters management portal
Vulnerable versions: production instance - Argentine Football Association (AFA) — Media portal
Vulnerable versions: production instance - Argentine Football Association (AFA) — Competition management system
Vulnerable versions: production instance - Argentine Football Association (AFA) — Institutional email account (mass-mail abuse)
Vulnerable versions: production instance
Remediation for Argentine Football Association (AFA) Breached via Year-Old
Immediate actions
- Force password resets for all AFA staff, developer, and administrative accounts, especially any tied to the compromised developer identity
- Revoke and rotate all credentials/API keys/session tokens associated with afasistemas.com.ar and any phpMyAdmin/DB admin accounts
- Enforce MFA on all administrative panels (phpMyAdmin, training HQ portal, media portal, competition management system)
- Search Hudson Rock / stealer-log aggregator databases for any organizational email domains to identify other dormant compromised-credential exposures
- Audit and disable any unauthorized mailbox rules, forwarding rules, or app passwords set on the abused institutional email account
- Notify affected staff, clubs, and media partners whose data appeared in the exfiltrated dataset
Workarounds
- Disable public/internet-facing exposure of phpMyAdmin and other DB-management panels pending access-control hardening
- Treat all outbound mail from the previously compromised institutional account as suspicious until forensic review completes
Longer-term hardening
- Implement organization-wide password-reuse detection and breached-credential monitoring (continuous stealer-log/dark-web monitoring)
- Deploy EDR with anti-infostealer / anti-credential-harvesting behavioral detection on all developer and administrative endpoints
- Adopt a password manager and unique-per-system credential policy to eliminate cross-system password reuse
- Segment administrative panels (phpMyAdmin, CMS, portals) behind VPN/zero-trust access with conditional access policies
- Establish a formal incident-response and breach-notification playbook for sports-federation IT staff
Weaknesses (CWE) in Argentine Football Association (AFA) Breached via Year-Old
CWE-1391, CWE-521, CWE-798, CWE-306
Timeline of Argentine Football Association (AFA) Breached via Year-Old
- Infostealer malware infects the personal/work device of a long-tenured AFA software developer, harvesting stored credentials for AFA systems.
- The compromised device and harvested credential set are logged into Hudson Rock's infostealer victim/Cavalier tracking database.
- Argentina defeats Egypt 3-2 in a World Cup Round-of-16 match marred by a VAR-overturned Egyptian goal, sparking public anger among Egyptian fans and officials over the refereeing by François Letexier.
- Threat actor group 'All Egyptian Cyber Warriors' leverages the dormant, reused stealer-log credentials to gain administrative access to AFA systems, including phpMyAdmin, root database access, the training HQ portal, media portal, and competition management system.
- AFA publicly acknowledges a possible unauthorized access incident, states the emails were not authorized by its staff, and begins an internal IT investigation.
- Attackers send mass emails from a legitimate AFA institutional email account to journalists worldwide with subject 'SYSTEM HACKED: UNFAIR DECISION,' protesting the match result and threatening further network disruption.
- AFA spokesperson indicates the immediate email-abuse situation has been addressed as investigation continues; media (Cybernews, tob.news) report on the hijacked account and threat actor messaging.
- Hudson Rock publishes research tying the breach to the year-old infostealer infection, and The Register reports the full incident and root-cause analysis.
- Stolen AFA data (staff/partner emails, phone numbers, user roles, access listings, hashed and some plaintext passwords) is advertised for sale on cybercrime forums.
Sources cited for Argentine Football Association (AFA) Breached via Year-Old
- World Cup grudge? Attackers may have scored Argentine FA access via year-old infostealer infection
- Hackers hijack Argentina football federation to demand "justice" for Egypt
- AFA hacked after Egyptian cyber group brands WC win a robbery
- Hudson Rock Cavalier infostealer intelligence platform
- MITRE ATT&CK: Valid Accounts (T1078)
- Infostealer Malware Triggers Major Database Breach at the Argentine Football Association
- Argentine Football Federation Formally Launches Comprehensive Cybersecurity Investigation Following Email Breaches
- Egyptian hackers break into Argentine FA system in retaliation for World Cup 'corruption'
Threats related to Argentine Football Association (AFA) Breached via Year-Old
Detection coverage for TL-2026-1265
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1265 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.