Overview
- The federation says a vulnerability in its Driver Categorisation Portal briefly allowed access to personal records for nearly 7,000 drivers, with Max Verstappen’s passport data theoretically reachable.
- Three independent researchers—Gal Nagli, Sam Curry and Ian Carroll—reported the flaw on June 3 and disclosed their findings publicly this week.
- By manipulating user roles via application-layer code, the researchers elevated privileges to admin level and viewed internal profiles and the classification dashboard.
- The FIA took the portal offline the day it was alerted and confirmed the fix on June 10, stating other digital platforms were not affected and a small number of drivers were notified.
- The researchers state they acted without malicious intent, halted testing upon confirming the exposure, deleted any downloaded data, and there is no public evidence of misuse.