Update: EA has published a statement on the matter. It claims that the issue has been fixed, and approximately 1600 players were affected.
An update on the EA SPORTS FIFA 20 Global Series registration page issue from October 3. pic.twitter.com/t5R6HwYd3I- EA SPORTS FIFA (@EASPORTSFIFA) October 4, 2019
The original story follows.
Electronic Arts announced its new FIFA 20 Global Series today, an international open competition for top players to compete in the realm of virtual football. But within hours, its registration page was taken down after a data breach was uncovered, leaving players' personal information freely available for others to see.
After the site went live, pro FIFA players like Kurt "Kurt0411" Fenech found that you could see previous registrants' personal information when you went to the sign-up page. Another player, George Huges, posted proof of this in action:
Jimmy "JREXX" Brennan shared attempts to log in via two-factor authentication spamming his phone as well. Alongside account information, personal details like date of birth and country were among the information reportedly visible.
EA has acknowledged the issue, tweeting that it would take down the registration page while it investigated the matter. The FIFA publisher also shared its security page, urging those affected to report issues directly to EA. We reached out for further comment, but did not hear back by the time of publication.
Some, like player Dan Watson, are already talking about potential GDPR consequences for the breach of personal data. It's unclear what the extent of the breach is so far, but those affected or who took part in registration today should probably ensure their account has two-factor authentication turned on, and then seek additional help via EA's security page.