Lionel Messi passport details leak in World Cup security blunder

Passport numbers of Argentina's World Cup squad, including Lionel Messi, were exposed due to a redaction oversight.

By Central
Passport details of Messi and teammates leaked at a World Cup warm-up match.
Highlights
  • The data leak occurred because passport numbers on the team sheet were not redacted as required by FIFA policy.
  • Exposed passport numbers increase risks of identity theft and fraud for high-profile players like Messi.
  • This incident follows a pattern of redaction failures seen in legal, corporate, and sports contexts globally.

An embarrassing security lapse at a World Cup warm-up match in Alabama has exposed the passport details of Argentina’s entire squad, including global superstar Lionel Messi, in an incident that underscores how easily sensitive data can slip out when organizations mistake the appearance of redaction for the real thing. The breach occurred ahead of Tuesday’s friendly against Iceland at Jordan-Hare Stadium, where an official team sheet containing the unredacted passport numbers of all 11 starters and substitutes was handed directly to journalists and released to the public. No hacker was involved — the failure was entirely procedural.

How Argentina’s Passport Data Leaked Before Kickoff

The team sheet, a standard document produced roughly an hour before each match under FIFA regulations, is normally prepared with sensitive fields obscured before distribution to the media. In this case, that critical redaction step was simply skipped. The document included the passport numbers of every Argentina player scheduled to participate, making them instantly accessible to the 88,000 spectators present and anyone who subsequently accessed the public match notes.

Why Passport Numbers Appear on World Cup Team Sheets At All

FIFA requires teams to submit passport numbers for every player approximately 60 minutes before kickoff. Referees and match officials use this data to verify that the players taking the field are who the team claims them to be and that they meet eligibility requirements. The rule exists because football organizations have, in the past, attempted to field fraudulently naturalized players, and the passport check provides a pre-match verification mechanism. The passport numbers serve a legitimate official purpose, but they are never meant to appear in the copies distributed to journalists, who typically receive a version with that information redacted. In Argentina’s case, that safeguard was entirely omitted.

Why Exposed Passport Data Poses a Real Security Risk

Passport numbers are a valuable commodity for criminals engaged in identity theft, travel document forgery, and building detailed profiles of high-net-worth individuals. For a figure like Messi, the exposure adds to an already elevated risk profile, but every player caught in the breach now faces an increased likelihood of targeted fraud attempts. The incident joins a troubling pattern of high-profile redaction failures where organizations believed they had protected sensitive information but had not.

A Pattern of Redaction Failures Across Government and Business

This is far from an isolated case. In January 2019, lawyers for former Trump campaign chairman Paul Manafort submitted court documents that appeared to contain black-box redactions, but the underlying text remained fully accessible to anyone who copied and pasted the content — revealing that Manafort had shared polling data with an alleged Russian intelligence associate. In 2023, Sony submitted a document during an antitrust hearing that included confidential details on publisher margins and Call of Duty revenues. The company had used a black Sharpie marker to redact sections, but the markings proved transparent when the document was scanned. Most recently, in December 2025, the US Department of Justice released millions of files related to Jeffrey Epstein, some of which used superficial black boxes that left the underlying data entirely accessible.

What All These Incidents Have in Common

The same fundamental error runs through each case: people confuse the appearance of redaction with actual redaction. A black box drawn over text in an electronic document does not guarantee that the text is gone. It may still be selectable, copyable, or recoverable, depending on the tool used to create and view the file. The solution is consistent across every context — whether you are an individual preparing a personal document, a company releasing a legal filing, or a football federation distributing a match-day team sheet. Before publishing any document that contains sensitive data, verify that the data has been permanently removed, not merely covered up.

What Affected Players and Individuals Should Do Now

Anyone whose passport number has been exposed in a breach of this kind should take immediate steps to reduce their risk of identity fraud. Enabling credit monitoring or a fraud alert with the major credit bureaus can provide early warning of suspicious account openings. Using a reputable identity theft protection service that monitors for passport-related fraud is a sensible next step. For everyday digital security, ensure that all accounts associated with the exposed individual — email, financial services, social media — are protected by strong, unique passwords and two-factor authentication. On public Wi-Fi or in high-risk environments, using a VPN with AES-256 encryption and a verified no-logs policy can help shield further personal data from interception. The key takeaway is straightforward: redaction is only effective when it is verified, not assumed. Whether you work in sports, law, government, or any other field that handles sensitive information, the same principle applies — check that the data is actually gone before you release the document.

Share This Article