Al Nassr FC and Asian Football Confederation: Is this 'the largest breach in football history'? Hackers allegedly breach Cristiano Ronaldo's Saudi team and AFC governing body, leak passports, contracts, and emails online

Al Nassr FC and Asian Football Confederation: Is this 'the largest breach in football history'? Hackers allegedly breach Cristiano Ronaldo's Saudi team and AFC governing body, leak passports, contracts, and emails online

AFC Suffers Massive Data Breach, Exposing Sensitive Information of 150,000+ Members

The Asian Football Confederation (AFC), the governing body for football in Asia, has reportedly fallen victim to a significant cyberattack, resulting in the exposure of highly sensitive data belonging to over 150,000 members. The breach, described by the threat actor as the "largest in football history," was advertised on the dark web marketplace PwnForums over the weekend.

The leaked records allegedly include passport scans, contracts, emails, and detailed player information, with data tied to prominent clubs such as Al Nassr FC home to stars like Cristiano Ronaldo, Sadio Mané, and Marcelo Brozović. Samples posted by the attacker also revealed full legal names, dates of birth, nationalities, player positions, AFC IDs, club affiliations, match details, and venue information.

Cybersecurity researchers at Dataminr warned that the combination of passport scans, verified email addresses, and contract data creates a high-risk scenario for financial fraud, contract manipulation, and targeted social engineering attacks against high-profile athletes. The threat actor, identified as a "forum-level operator," claimed assistance from the notorious ShinyHunters group to lend credibility to the leak, though no direct affiliation was confirmed.

As of the latest reports, the AFC has not issued an official statement regarding the breach. The incident underscores the growing threat to sports organizations and the potential for cybercriminals to exploit stolen data for malicious purposes.

Source: https://www.techradar.com/pro/security/is-this-the-largest-breach-in-football-history-hackers-allegedly-breach-cristiano-ronaldos-saudi-team-and-afc-governing-body-leak-passports-contracts-and-emails-online

Asian Development Bank (ADB) cybersecurity rating report: https://www.rankiteo.com/company/asian-development-bank

شركة نادي النصر - ALNASSR Club Company cybersecurity rating report: https://www.rankiteo.com/company/alnassr

"id": "ASIALN1777487604",
"linkid": "asian-development-bank, alnassr",
"type": "Breach",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '150,000+ members',
                        'industry': 'Sports',
                        'location': 'Asia',
                        'name': 'Asian Football Confederation (AFC)',
                        'type': 'Sports Governing Body'},
                       {'industry': 'Sports',
                        'name': 'Al Nassr FC',
                        'type': 'Football Club'}],
 'data_breach': {'data_exfiltration': 'Yes',
                 'file_types_exposed': ['Scans', 'Documents', 'Emails'],
                 'number_of_records_exposed': '150,000+',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Passport scans',
                                              'Contracts',
                                              'Emails',
                                              'Player information',
                                              'Full legal names',
                                              'Dates of birth',
                                              'Nationalities',
                                              'Player positions',
                                              'AFC IDs',
                                              'Club affiliations',
                                              'Match details',
                                              'Venue information']},
 'description': 'The Asian Football Confederation (AFC), the governing body '
                'for football in Asia, has reportedly fallen victim to a '
                'significant cyberattack, resulting in the exposure of highly '
                'sensitive data belonging to over 150,000 members. The breach '
                'was advertised on the dark web marketplace PwnForums and '
                'includes passport scans, contracts, emails, and detailed '
                'player information tied to prominent clubs such as Al Nassr '
                'FC.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Passport scans, contracts, emails, player '
                                'information, full legal names, dates of '
                                'birth, nationalities, player positions, AFC '
                                'IDs, club affiliations, match details, venue '
                                'information',
            'identity_theft_risk': 'High'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Yes',
                           'high_value_targets': 'High-profile athletes (e.g., '
                                                 'Cristiano Ronaldo, Sadio '
                                                 'Mané, Marcelo Brozović)'},
 'motivation': 'Financial fraud, contract manipulation, targeted social '
               'engineering attacks',
 'references': [{'source': 'Dataminr'},
                {'source': 'PwnForums (dark web marketplace)'}],
 'threat_actor': 'Forum-level operator (allegedly assisted by ShinyHunters '
                 'group)',
 'title': 'AFC Suffers Massive Data Breach, Exposing Sensitive Information of '
          '150,000+ Members',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.