SECURITY DESK / MOTORSPORT

When the paddock
gets breached

Formula 1 runs on data — telemetry, aero models, strategy calls, sponsor logins, driver PII. That makes every team, and the FIA itself, a target. A recorded history of the sport's espionage cases, intrusions, and digital sabotage, sector by sector.

10
Documented incidents
18
Years on record
6
Teams & bodies affected
$100M+
Largest single penalty

Not just a racing series

F1's attack surface has grown alongside its technology stack: fan apps, AR launches, driver-data portals, sponsor infrastructure, and factory networks worth defending like any critical enterprise. Some of these cases are classic industrial espionage carried out on paper and USB drives. Others are modern intrusions — ransomware, phishing, and app compromises — aimed at teams and the FIA alike.

Incident log

SEVERITY — ● HIGH ● MED ● LOW
2007
Industrial espionage

McLaren / Ferrari — "Spygate"

McLaren's chief designer was found in possession of a dossier of more than 780 pages of confidential Ferrari technical documentation, obtained through a Ferrari employee. The FIA ruled McLaren had used the material, fining the team $100 million and stripping its constructors' championship points for the season — the largest penalty in the sport's history and still the reference case for what F1 espionage can cost.

SOURCE: FIA WORLD MOTOR SPORT COUNCIL RULING
2011
Network intrusion

Renault F1 Team — Data theft for resale

Hackers gained access to confidential Renault technical and strategic files. The intrusion was traced to a group based in Eastern Europe reportedly attempting to sell the stolen material to rival constructors. No leak was confirmed, but the FIA used the case to push teams toward stronger network security.

SOURCE: FIA ADVISORY / MOTORSPORT SECURITY REPORTING
2015
Insider data theft

Mercedes — Departing-engineer copy case

Mercedes took legal action against a former engineer accused of copying engine mileage, damage logs, and raw telemetry from the 2015 Hungarian Grand Prix before moving to Ferrari — a reminder that F1's biggest data-security risk is sometimes a badge, not a firewall.

SOURCE: CIVIL PROCEEDINGS, MERCEDES-AMG PETRONAS
2020
Disputed design origin

Racing Point — Brake-duct ruling

The FIA found Racing Point's brake ducts to be a close copy of the previous year's championship-winning Mercedes design, fining the team $427,000 and docking 15 points. The governing body never confirmed a digital breach, but the case fuelled speculation about how closely a rival's design files had been accessed.

SOURCE: FIA STEWARDS' DECISION, 2020
MAR 2021
App compromise

Williams Racing — FW43B reveal hijacked

Hours before Williams planned to unveil its 2021 car through an augmented-reality app, attackers compromised the app itself. Livery images leaked early and the launch was cancelled outright, with Williams pulling the app from both major stores. The team said its core in-house systems were untouched — the breach lived entirely in third-party app infrastructure.

SOURCE: WILLIAMS RACING STATEMENT, MAR 2021
JUL 2021
Push-notification hijack

Official F1 App — "I should check my security"

Over 5 million users of the official F1 mobile app received two unauthorised push notifications — the first reading simply "foo," the second a taunting "Hmmmm, I should check my security.. :)". F1 confirmed its push-notification service had been compromised in a targeted attack, though no customer data was believed accessed.

SOURCE: F1 OFFICIAL STATEMENT, JUL 2021
2022
Ransomware

Ferrari — RansomEXX & NFT scam

A ransomware group calling itself RansomEXX claimed to have exfiltrated roughly 7 gigabytes of internal Ferrari documents and manuals, shortly after the team ended its cybersecurity partnership with Kaspersky. Months later a Ferrari brand subdomain was separately compromised and used to host a fraudulent NFT drop before being taken down.

SOURCE: THREAT-INTEL REPORTING, 2022
2024
Phishing

FIA — Staff email compromise

The FIA disclosed that phishing attacks led to unauthorised access of two staff email accounts, exposing personal data. The governing body cut off access quickly and notified both French and Swiss data-protection regulators, describing it as part of a wider phishing campaign across the motorsport world rather than a targeted hit.

SOURCE: FIA PUBLIC DISCLOSURE, 2024
2024
Fan-facing phishing

Belgian Grand Prix — Spa ticket-voucher scam

Attackers broke into the Belgian Grand Prix's official contact mailbox and used it to blast fans with a fake €50 ticket voucher, directing them to a spoofed portal built to harvest payment details. Organisers flagged the fraud within hours and filed a criminal complaint.

SOURCE: SPA GP INCIDENT STATEMENT, 2024
2025
Data exposure

FIA Driver Portal — Verstappen PII exposed

Security researchers testing the FIA's driver-categorisation website found they could grant themselves administrator access, exposing passports, licences, résumés, and password hashes for the sport's drivers — including Max Verstappen. The researchers stopped once the scope became clear and disclosed responsibly; the FIA confirmed the breach and patched the site.

SOURCE: RESEARCHER DISCLOSURE, FIA CONFIRMATION, OCT 2025