On 1 February 2024, Australian media reported research by Cybernews, a Lithuania-based research team, showing that Football Australia, the sport's national governing body, had left Amazon Web Services (AWS) access keys in plain text in the HTML of one of its subdomains. According to Cybernews, as reported by Cyber Daily and The Canberra Times, the keys, including secret keys, gave access to 127 cloud storage buckets holding ticket buyers' personal details, player contracts and documents, internal infrastructure details and source code. One bucket needed no authentication at all. Cybernews said it contacted Football Australia, which fixed the exposure before the findings were published. Football Australia confirmed "the inadvertent exposure of certain credentials" on its FIFA Connect system, said it was fixed within hours of the organisation becoming aware, and disputed parts of the media coverage, including any access to international player contracts. No misuse by anyone other than the researchers has been reported.
Key takeaways
- Cybernews found plain-text AWS keys, including secret keys, hard-coded into the HTML of a Football Australia subdomain, where anyone reading the page source could find them.
- The keys reportedly opened 127 storage buckets. Cybernews said they held players' personal information, contracts and documents, ticket purchase data, infrastructure details and source code, and that one bucket required no authentication.
- Cybernews could not say how many people were affected without downloading the data, but estimated "that every customer or fan of Australian football was affected". That is the researchers' estimate, not a confirmed count.
- Football Australia confirmed an inadvertent credential exposure on its FIFA Connect system and said it was fixed within hours, but called one media report "highly speculative" and denied that international player contracts were reachable. No misuse has been confirmed.
- The identity lesson: a long-lived cloud access key placed in front-end code is a public credential, and whatever it can reach should be treated as public too.
At a glance
| Organisation | Football Australia (national governing body for football in Australia) |
|---|---|
| When | Exposure start not confirmed (the Cloud Security Alliance later put it at more than 700 days); first reported 1 February 2024; Football Australia's second statement 3 February 2024 |
| Attacker | None known. Found by the Cybernews research team |
| Entry point | AWS access keys, including secret keys, hard-coded in plain text in the HTML of a public Football Australia subdomain |
| Identities abused | AWS access keys with access to 127 storage buckets, according to Cybernews |
| Impact | Player, ticket buyer and internal data reported reachable; no confirmed misuse. Football Australia says the exposure was fixed within hours and disputes parts of the reported scope |
| Category | NHI. Incident class: exposure, no confirmed misuse (cloud access keys published in website code) |
What happened
Cybernews researchers were examining Football Australia's web presence when they found AWS keys written in plain text into the HTML of a subdomain, The Canberra Times and Cyber Daily reported. According to Cyber Daily, the secret keys gave access to the organisation's AWS services and the ability to control them, including 127 digital storage containers. Cybernews described the case as a "critical data exposure incident" and said the most likely cause was human error, as a developer "likely inadvertently left a reference hidden in a script accessible to the public."
Cybernews said the buckets held personal details of ticket buyers, player contracts and documents (Australasian Leisure Management's report adds passports), internal infrastructure details, and source code and scripts for Football Australia's digital services. One bucket "did not even require authentication", the researchers told Cyber Daily. They did not download the full dataset, saying that would conflict with their responsible disclosure policy, so they could not count the people affected. They warned that the data "poses a severe threat as attackers could exploit this information for identity theft, fraud, or even blackmail", as quoted by The Canberra Times.
Football Australia first responded on Thursday 1 February: "Football Australia is aware of reports of a possible data breach and is investigating the matter as a priority." On Saturday 3 February, responding to a 7 News Sydney report, it said that report "contains several inaccuracies and was highly speculative". It said: "Although we are aware of the inadvertent exposure of certain credentials on Football Australia's FIFA Connect System", the credentials "did not provide access to information such as international player contracts", and that the suggestion community registration platforms were at risk was misleading. "Football Australia acted swiftly and remedied that exposure within hours of becoming aware," it said, according to Australasian Leisure Management. FIFA Connect is FIFA's system for member associations to register players, coaches and referees.
A Cloud Security Alliance case study published in June 2025 said the data had been exposed for "over 700 days" and that an AWS long-term access key had been embedded in the source code. Football Australia has not confirmed how long the keys were exposed.
Timeline
| Date | Event |
|---|---|
| 2024 | Before publication, Cybernews finds the keys and contacts Football Australia, which fixes the exposure before publication, according to Australasian Leisure Management. |
| 1 February 2024 | Cybernews' findings are reported by Cyber Daily and The Canberra Times; Football Australia says it is investigating. |
| 3 February 2024 | Football Australia confirms an inadvertent credential exposure on FIFA Connect, says it was fixed within hours and disputes parts of the coverage. |
| 9 June 2025 | The Cloud Security Alliance publishes a case study saying the data was exposed for more than 700 days. |
How it happened: the identity attack path
- Static cloud key created. Football Australia's environment used AWS access keys, long-lived credentials that work from anywhere until revoked.
- Key placed in front-end code. The keys, including the secret part, were hard-coded into a script in the HTML of a public subdomain, likely by developer error according to Cybernews.
- Key found in page source. Anyone reading the page could copy the keys; Cybernews did exactly that.
- Broad storage access. The keys reportedly reached 127 storage buckets holding player, fan and internal data, and one bucket was open without any credential, according to Cybernews.
- Revocation. After Cybernews made contact, Football Australia fixed the exposure, which it says took hours.
Impact
- Confirmed by Football Australia: certain credentials on its FIFA Connect system were inadvertently exposed and then remedied.
- Reported by Cybernews: access to 127 buckets containing players' personal information, contracts and documents, ticket buyers' details, infrastructure details and source code. Football Australia disputes that international player contracts or community registration platforms were at risk.
- Not established: the number of people affected. Cybernews estimated every customer or fan of Australian football; no count has been published.
- Misuse: none confirmed. No source reports anyone other than the researchers using the keys.
What this means for NHI governance
An AWS access key is a machine identity: a credential that lets software act in a cloud account without a person signing in. When it is placed in website code, it stops being secret the moment the page is published. Every visitor's browser downloads it. The breadth of what the key could reach turned a coding mistake into exposure of a whole organisation's storage, because one key appears to have had access to well over a hundred buckets.
Two controls would each have limited the damage. Front-end code should never hold cloud secrets; browsers that need to upload or fetch files should get short-lived, narrowly scoped URLs or tokens issued by a back end. And each key should only reach the resources its job needs, so a leaked key exposes one bucket, not 127. Our Secrets Management Guide and Cloud Workload Identity Guide cover both.
Recommendations
- Revoke and rotate exposed keys immediately, then review their use. Deactivate the key, issue a new one only if still needed, and check CloudTrail for every action taken with the old key. See the Leaked Credential Response Playbook.
- Never put cloud secrets in front-end code. Issue short-lived, pre-signed URLs or scoped temporary credentials from a back end instead. See our Secrets Management Guide.
- Replace long-lived access keys with roles and temporary credentials. Workloads running in AWS should use IAM roles, not static keys. See our Cloud Workload Identity Guide.
- Scope each key to the buckets it needs. Review IAM policies so no single credential can list and read every bucket in the account. See our Cloud PAM and CIEM Guide.
- Scan published web content, not just repositories, for secrets. Include built JavaScript and HTML on public sites in secret scanning, and block deployments that contain keys.
- Turn on S3 Block Public Access across the account. One bucket in this case needed no credential at all.
Frequently asked questions
What happened in the Football Australia data leak?
In early 2024 Cybernews found AWS access keys in plain text in the HTML of a Football Australia subdomain. The keys reportedly gave access to 127 storage buckets holding player, fan and internal data. Football Australia confirmed a credential exposure on its FIFA Connect system and said it fixed it within hours.
Was Football Australia's data stolen?
No theft or misuse has been confirmed. Cybernews reported the data as reachable and did not download it. Football Australia said some media reports were inaccurate and that the exposed credentials did not give access to international player contracts.
How did AWS keys end up on Football Australia's website?
Cybernews said a developer likely left a reference to the keys hidden in a script that was publicly accessible, putting both the access key and the secret key into the page's HTML.
Related NHI Mgmt Group resources
Mercedes-Benz GitHub Token Exposure 2024 · Toyota T-Connect Key Exposure 2022 · 230 Million AWS Cloud Environments Campaign 2024 · Secrets Management Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Static cloud keys left in code are among the most common causes of exposure in our breach database. We help organisations find them, scope them down and replace them with short-lived credentials. See our NHI and AI agent security training.
References
- Cyber Daily: Personal data exposed in Football Australia data leak after database left accesible (1 February 2024)
- The Canberra Times: Possible 'critical' data leak impacts Football Australia, players, ticket-buyers (1 February 2024)
- Australasian Leisure Management: Football Australia reveals data breach (3 February 2024)
- Cloud Security Alliance: The 2024 Football Australia Data Breach: A Case of Misconfiguration and Inadequate Change Control (9 June 2025)