Argentina's Football Association Says Its Email Account May Have Been Hacked After World Cup Win
Someone sent journalists messages from the AFA's official inbox claiming Argentina's victory over Egypt was fixed. The association says it didn't send them.

Key points
- The Argentine Football Association (AFA) warned in 2025 that one of its official email accounts may have been accessed without permission.
- Emails sent from that account to journalists claimed Argentina "did not win" its 3-2 World Cup comeback victory over Egypt and blamed "corrupt refereeing decisions".
- The AFA said it didn't generate or authorise the messages and is investigating.
- AFA sources told Argentine outlet La Calle that hackers of Egyptian origin were believed to be responsible.
- The AFA is asking anyone who received an unusual message from its account to ignore it, especially if it contains links or requests personal information.
Argentina were trailing Egypt 2-0 and facing an early World Cup exit before clawing back three goals to win. Then the inbox drama started.
After the match, emails landed in journalists' inboxes carrying the AFA's official address. The messages said Argentina hadn't really won, and that the result came down to corrupt officials. They also praised Egypt's performance. As BBC News first reported, the Egyptian Football Association had already asked FIFA, the sport's global governing body, to remove French referee Francois Letexier from the tournament, alleging he had favoured Argentina.
Could those emails have actually come from the AFA?
No. The AFA says its own staff didn't write or send them. In a public statement the association said it had "detected the possible sending of emails from one of our institutional accounts that were not generated or authorised by our team." That's polite language for: someone else got into the account and hit send.
AFA sources told La Calle they suspect hackers with ties to Egypt were behind it. No individual or group has been named publicly, and no arrests have been announced.
The failure mode is familiar. Email accounts, even official organisational ones, can be broken into if passwords are weak or stolen through phishing, where criminals send fake messages designed to trick someone into handing over their login credentials. One staff member clicking the wrong link can hand an outsider full access to a shared inbox. We've covered that attack path in detail, including how a phishing crew recently walked Microsoft 365 users straight through Microsoft's own device sign-in flow.
Should you worry if you got one of these emails?
Delete it. Don't click any links inside it, don't open attachments, and don't enter personal details if prompted. The account may still be accessible to whoever broke in, so treat anything from it as hostile until the AFA confirms otherwise.
What the post-mortem will almost certainly find: no multi-factor authentication. MFA, meaning a second confirmation step beyond a password such as a code sent to your phone, makes it far harder for an outsider to log in even with the correct credentials. The AFA says it's working to lock the account down and understand how the access happened.
The blunt read here: shared team inboxes are high-value targets that sit at the bottom of the security to-do list until something like this happens. That ordering needs to change before the next big match.



