A leak of credentials and email addresses during calls to the nfl.com domain was detected in the NFL Mobile App, which is popular due to the Super Bowl.
The process takes place immediately after the user enters the app in a secure manner, as a result of a secondary, unencrypted API and a cookie.
The mobile app is designed to deliver breaking news, highlights and game scores to NFL fans
Mobile data gateway company Wandera identified the security holes through its scanning technologies and discovered that the leaked data could be used to access an NFL.com account . This process also occurs over a secure connection, which means the traffic can be intercepted through a man-in-the-middle attack.
In addition to username and password, data associated with a profile on NFL.com includes email and postal address, phone number, occupation, date of birth, as well as social media connections and NFL- (favorite team, etc.).
Eldar Tuvey , CEO of Wandera, said that 23% of the company's US clients have at least one employee with the vulnerable app available on a personal device, and that he expects the number of app installs to increase as the Super Bowl approaches .
"It's ironic that just as a quarterback is vulnerable to hacking, the NFL is vulnerable to a man-in-the-middle that puts user data at risk of being intercepted by hackers," Tuvey added.
As for financial information, Wondera 's review does not include commodity trading, so it is not clear whether this type of information is also exposed due to the insecure traffic from the mobile app.
"We have not yet tested other NFL apps, such as 'NFL Now', 'NFL Fantasy Football', etc. They potentially have similar vulnerabilities," Tuvey said Tuesday.

