Security researchers say a simple security flaw gave her access to several internal FIFA platforms, which allowed her to watch and take full control of the TV stream of every World Cup match.
The researcher, known as BobDaHacker, said he only registered as a player agent on FIFA's official agent registration platform. She was then able to access several internal FIFA platforms thanks to having that account and a flaw in FIFA's backend API that did not check whether the user actually had the proper permissions.
Researchers say this included a system that allowed broadcasters to control what was shown on people's TVs around the world, as well as what was shown on the screens of commentators narrating the matches.
“A single attacker could hijack all cameras at the same time. An attacker could also have stolen the entire FIFA World Cup,” BobDaHacker said in a blog post published Tuesday.
BobDaHacker reported the flaw on Tuesday night Japan time, and FIFA fixed the issue hours later without acknowledging any of the researcher's report.
FIFA did not immediately respond to TechCrunch's request for comment.

