Hackers access F1 drivers’ private data in FIA security breach

Photo: Getty Images / Red Bull Content Pool

23. 10. 2025 18:12 CET
icon timer
2 min

Hackers access F1 drivers’ private data in FIA security breach

Tereza Hořínková

Tereza Hořínková

News.GP journalist specialising in F1 and MotoGP

Formula 1 f1 f12025season fia f1update

Hackers briefly accessed the personal data of hundreds of Formula 1 drivers, including Max Verstappen, after discovering a serious vulnerability in the FIA’s driver categorisation portal.

F1 & MotoGP news to your inbox every day.

Earlier this summer, hackers briefly got access to the personal information of hundreds of racing drivers, including four-time Formula 1 world champion Max Verstappen, after a security breach in the FIA’s driver categorisation portal. The breach allowed them to see sensitive data such as passports, driver licences, and personal contact details.

X user Nagli, who calls himself “Hacker” and “Head of Threat Exposure at @wiz_io”, revealed on X that he, along with Sam Curry and Ian Carroll, were testing what they described as “the security of the whole ecosystem.” They created a driver page on the portal and decided to test a theory to see if they could become an admin for the system. “It took us 10 minutes using one simple security flaw,” Nagli wrote on X. “We were looking at the security of the whole ecosystem. That’s how we stumbled upon a severe vulnerability in a critical portal managed by the FIA that was reported and fixed in less than 24 hours.”

Once they became admins, Nagli and his colleagues were able to access the personal data of every driver in the system. “We found a way to access Max Verstappen’s passport, driver’s licence, and personal information along with every other Formula 1 driver’s sensitive data,” he said. However, he stressed that they did not download or save any passports or sensitive information. “All test data was deleted. No driver information was compromised by us,” he added. These comments were reported by PlanetF1.

The trio worked with the FIA to resolve the issue and reported the flaw immediately. “We worked with the FIA to promptly fix the issue. Shoutout to their team for the rapid response and taking the matter seriously,” Nagli said.

An FIA spokesperson told PlanetF1 to the matter: “Immediate steps were taken to secure drivers’ data, and the FIA reported this issue to the applicable data protection authorities in accordance with the FIA’s obligations. It has also notified the small number of drivers impacted by this issue. No other FIA digital platforms were impacted in this incident.”

The cause of the breach was explained as a bug called “mass assignment,” where the system trusted a request to become an admin without checking if the account had permission. The FIA added that it has invested extensively in cybersecurity and resilience measures across its digital estate and implements a policy of security-by-design in all new digital initiatives.

This is not the first time the FIA has faced a hack. Last year, phishing attacks allowed unauthorised access to personal data in two FIA email accounts. At the time, the FIA told TechRadar that it took all actions to stop the access and notified the relevant French and Swiss data protection authorities.

logo-newsgp logo-instagram logo-linkedin logo-whatsapp

Tereza Hořínková

Tereza is a dedicated sports journalist and mass media student, who has been passionate about the motorsport world since young age. Her work focuses on the stories on and off the track, while making motorsport feel accessible and exciting for every kind of fan.

To the topic

F1 & MotoGP news to your inbox every day.

logo-newsgp
Information

icon F1 and MotoGPF1 and MotoGP news

icon articlesNew articles every day

icon worldNews from around the world

icon reportsReports from races

logo-newsgp logo-instagram logo-linkedin logo-x logo-whatsapp logo-youtube

F1 & MotoGP news around the globe

Contact

NewsGP s.r.o.
Nové Sady 988/2
602 00, Brno, Czechia
IČO 22343776
European Union

info@news.gp


We have established partnerships with circuits, organizers, and official partners. As we do not collaborate directly with the owner of the Formula 1 licensing, it is necessary for us to include the following statement:

This website is unofficial and is not associated in any way with the Formula 1 companies. F1, FORMULA ONE, FORMULA 1, FIA FORMULA ONE WORLD CHAMPIONSHIP, GRAND PRIX and related marks are trade marks of Formula One Licensing B.V.