The AFA has opened a formal investigation and warned people to ignore suspicious messages asking for personal information or containing unfamiliar links.
Why Argentina’s win over Egypt was already under scrutiny
The cyber incident followed a match already surrounded by anger and suspicion.
Egypt had taken a 2-0 lead through goals from Yasser Ibrahim and Mostafa Ziko. The controversy grew after a second goal from Ziko was ruled out and Egypt had a penalty appeal rejected.
Argentina then completed the comeback, with Enzo Fernández scoring the winner in the 92nd minute.
That finish intensified Egypt’s frustration. The Egyptian Football Association has filed a formal complaint with FIFA and called for referee François Letexier to be removed.
Egypt manager Hossam Hassan suggested there had been pressure on officials that worked in Argentina’s favor. Ziko went further, publicly saying the tournament was “fixed.”
FIFA defended the match officials
FIFA’s chief refereeing officer Pierluigi Collina rejected criticism of the officiating team.
Collina said “nobody can question the integrity” of referees at the tournament, defending the officials as scrutiny of the match continued.
For supporters, the issue now has two layers: the original anger over the decisions on the pitch, and the security breach that made the governing body appear to criticize its own team’s victory. Convenient? No. Believable as official messaging? Also no, according to the AFA.
Official organizations remain tempting targets
The AFA breach fits a broader pattern of cyber incidents hitting major organizations and platforms.
Discord confirmed a similar issue last year after a third-party breach exposed sensitive user data. The company later said the breach came through a vendor, not Discord’s own systems.
For sports bodies, the risk is especially awkward. Their official channels carry authority, and when those channels are compromised during a controversy, the damage spreads quickly. In this case, the AFA is trying to make clear that the emails were the result of unauthorized access, not an extraordinary act of self-incrimination.