FIFA 20’s first pro competition of the year kicks off with a data leak

Professional players, YouTubers and streamers all hit by the Electronic Arts blunder

Jadon Sancho in FIFA 20

Professional FIFA 20 esports players have been the subject of a data leak after signing up to the first professional competition of the annually released game's life cycle.

The game is less than a week old, but when a number of players registered for the FIFA 20 Global Series, they were met with an online form that was pre-filled with the personal information of players who had already registered.

Pro players, YouTubers, streamers and other registrants took to Twitter to voice their anger at Electronic Arts, the company behind the game.

Prominent Twitch streamer Kurt0411 blasted the company in a particularly emotive reaction, seen by his 61.8k Twitter followers, later following up by claiming he would sue the company for its wrongdoing.

The official online form provided by EA Sports which players were met with can be seen in the screenshot below. Players' names, dates of birth, account IDs and location could be viewed by the user, all pre-filled in the form's data fields.

UK-based professional player JREXX tweeted a screenshot of the myriad two-factor authentication (2FA) texts he received following the incident, adding that he thought it was "a shambles".

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"If the allegations are true, this could mean that players have been leaked the sensitive details necessary to login to other people's accounts," said Ray Walsh, digital privacy expert at ProPrivacy.com. "At the moment the scale of the data breach is unknown. However, it's like there is the potential for the exposed data to be used for targeted phishing attempts on those affected."

"It is unclear at this time whether updating the password for your account will help, but users are advised to do so as a precaution, as well as keeping an eye on any bank accounts that may be linked to their player IDs."

EA Sports initially acknowledged "a potential issue" on Thursday afternoon but twelve hours later the company released a more extensive admission of fault, in the early hours of Friday morning (BST).

"At approximately 1 pm UK time, we announced the registration portal page for the EA Sports FIFA 20 Global Series. Shortly after, we learned that some players trying to register were seeing the information of other players who had already signed-up through the registration page, the company said in a statement posted to Twitter.

Advertisement - Article continues below

"We immediately took action to shut down the site by 1:30 pm UK time. We were able to root cause the issue and implement a fix to be clear that information is protected. We're confident that players will not see the same issue going forward."

The company said it determined around 1,600 of registrants were affected by the issue and it was working hard to contact them to secure their accounts.

Somewhat ironically, the incident took place just days after the company enticed its user base to enable 2FA on their accounts, doing so would see them rewarded with a free month of Origin Access.

"If UK citizens are affected by a data breach then the organisation should notify the ICO within 72 hours of becoming aware of it unless it does not pose a risk to people's rights and freedoms," said an ICO spokesperson. "If an organisation decides that a breach doesn't need to be reported they should keep their own record of it, and be able to explain why it wasn't reported if necessary."

IT Pro has contacted EA for further comment and but it declined to provide any.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/hardware/354584/windows-10-and-the-tools-for-agile-working
Sponsored

Windows 10 and the tools for agile working

20 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020