drj logo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Spring 2026
    • DRJ Fall 2026
    • DRJ Scholarship
    • Tracey Rice Memorial Scholarship
    • Other Industry Events
    • Schedule & Archive
  • WEBINARS
    • Upcoming Webinars
    • On Demand
    • DRJ Showcase Series
  • MENTOR PROGRAM
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • DRJ Glossary of Business Continuity Terms
    • Careers
    • The BCI Partnership
  • ABOUT
    • About DRJ
    • 2026 Media Kit
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • DEI
      • Glossary Committee
      • Rules and Regulations Committee

Cybercriminals Are Targeting the FIFA World Cup 2026

by Jon Seals | June 4, 2026 | | 0 comments

FortiGuard Labs research shows how threat actors are using tournament demand to launch scams and steal credentials

This post first appeared on the Fortinet blog.

By FortiGuard Labs

Starting June 11, the FIFA World Cup 2026 will unite fans, teams, sponsors, broadcasters, hospitality providers, and businesses in one of the world’s largest sporting events. It also presents a significant opportunity for cybercriminals.

Major international sporting events create great anticipation, attract high search volume, evoke strong emotions, and drive large volumes of digital transactions. Fans are searching for tickets, travel offers, merchandise, live streams, betting sites, job openings, and event updates. Meanwhile, organizations are busy with logistics, staffing, travel arrangements, customer service, media tasks, and coordinating with third parties. Threat actors have anticipated these scenarios and have already started exploiting them.

New research from FortiGuard Labs reveals that cybercriminal infrastructure linked to the FIFA World Cup 2026 is already operational. From January to May 2026, more than 13,000 new FIFA World Cup 2026–themed domains were registered. And about 8.8% of these domains have been identified as malicious or suspicious through pattern analysis and scam activity.

That volume shows that threat actors are not waiting for the opening match. They are already here.

A Fast-Growing Threat Landscape

Our research has revealed a significant increase in FIFA-themed domain registrations from March to May 2026, with many domains misusing FIFA branding and including terms related to ticketing, streaming services, betting platforms, and hospitality.

Threat actors have created hundreds of fake websites that appear legitimate enough to earn fans’ trust for a few critical seconds while they search for tickets, resale options, match streams, travel packages, and official merchandise. Those few seconds are often all they require.

The report identifies several major categories of FIFA-themed threats:

  • Phishing and fake ticketing websites
  • Resale ticket scams promoted through Telegram and other channels
  • Fake merchandise storefronts
  • Malicious betting and streaming applications
  • Third-party Android Package Kit (APK) downloads carrying potential malware risk
  • Social media impersonation accounts
  • Fake job postings and recruitment lures
  • Cryptocurrency scams and fake airdrops
  • Credential exposure tied to stealer malware and historical breach data

These findings suggest the development of a wide-ranging cybercrime ecosystem centered around the tournament. This threat extends well beyond a single scam type, platform, or victim demographic.

Fake Ticketing Remains One of the Highest-Risk Lures

Ticketing scams are among the most visible threats because they exploit scarcity. Fans unable to secure tickets through official channels often turn to resale websites, social media groups, Telegram channels, search ads, or peer-to-peer marketplaces. Attackers capitalize on this urgency by promoting bogus limited-time discounts to pressure victims into making quick decisions.

FortiGuard Labs identified numerous counterfeit ticketing sites mimicking official FIFA pages that gather personal info, login details, billing, and payment data. In one case, a domain registered in May 2026 replicated FIFA content and employed a fake checkout to harvest victims’ sensitive information.

The report also documents ticket scams advertised on underground forums and Telegram channels. Some campaigns bundled fraudulent match tickets with counterfeit flight and hotel packages to make the offers appear more complete and credible.

These scams work because they anticipate typical fan behavior. A user trying to buy a ticket may not think like a security analyst. They are trying to secure a seat before it disappears.

Social Media Impersonation Expands the Attack Surface

FortiGuard Labs identified more than 1,700 suspected FIFA-related impersonation accounts and channels across social media and messaging platforms. Nearly 90% of these cases were on Facebook and Instagram.

These accounts can be exploited for fake promotions, ticket scams, fraudulent livestream links, phishing, misinformation, and malware distribution. Additionally, they offer attackers an inexpensive method to contact fans directly, as fans frequently discuss teams, matches, travel plans, and ticket availability.

Social media scams are particularly convincing because they often appear within legitimate conversations. For instance, a fake ticket seller in a fan group, a livestream link shared just before a match, or an account with FIFA branding can seem credible enough to prompt a click.

Malware Is Also Part of the Tournament Threat Landscape

The report highlights malicious apps linked to World Cup–related activities. One detected executable, ‘1xbet.exe,’ shows signs of persistence, encrypted communications, and possible ransomware behavior. FortiGuard Labs additionally found suspicious FIFA-themed APK files on third-party download sites.

This is crucial because major sporting events frequently increase the demand for betting apps, livestreaming tools, score trackers, and promotional apps. Attackers exploit this demand by distributing fake or trojanized software that appears to be legitimate.

Installing apps from unofficial sources can expose devices to spyware, credential theft, remote access tools, or other malware. This risk increases when users ignore security warnings to access streams, promotions, or betting platforms.

Fake Job Postings Target People Looking for Opportunity

The World Cup also generates demand for temporary workers, contractors, hospitality staff, logistics personnel, media support, and event-specific roles. This demand provides attackers with another attractive target.

For example, FortiGuard Labs identified a credential-stealing scheme that used fake FIFA-related job ads and sponsor recruitment posts. The attackers sent calendar invites and directed victims to phishing websites with a counterfeit Google login page. When victims entered their credentials, they received a generic error message, enabling the attackers to capture their information.

Multiple domains impersonating FIFA, sponsors, and affiliated organizations shared the same Google Analytics tracking ID, pointing to a coordinated campaign. The credential theft process employed Render-hosted APIs, showcasing how attackers can exploit legitimate cloud services to deploy malicious infrastructure more easily and make it difficult to differentiate from regular web activity.

Credential Exposure Raises the Stakes

The report also found evidence of FIFA-related activity within stealer log telemetry. FortiGuard Labs detected over 4,600 URLs associated with FIFA in stealer logs, connected to malware families like Vidar, LummaC2, and RedLine. Additionally, the research uncovered more than 260 FIFA employee credentials and over 270,000 credentials from users and fans visiting FIFA-related websites in delimiter-based stealer log data.

Additionally, FortiGuard Labs found over 1,500 records of FIFA-related employee and organizational accounts in past breach datasets.

This does not imply that all exposed accounts are currently active or being exploited. However, threat actors now have access to data that could facilitate credential stuffing, account takeover, targeted phishing, impersonation, and fraud. During high-profile global events, even outdated credentials can be exploited when combined with new social engineering tactics and lures.

What You Should Do Now

The FIFA World Cup 2026 threat landscape is a reminder that significant events present cyber risks well before they begin. As a result, organizations in sports, travel, hospitality, media, retail, finance, government, transportation, and critical infrastructure need to start their defensive preparations early.

Security teams need to monitor for lookalike domains, brand impersonation, malicious advertisements, fake social media profiles, and credential leaks involving employees, partners, and customers. They should also assess protections against phishing, malware, credential theft, and account takeovers.

User education is important. Fans and employees should be reminded to use official ticketing channels, avoid third-party APKs, exercise caution with livestream links, verify job postings on official websites, and be wary of urgent payment requests that seem suspicious.

For defenders, the most critical lesson is straightforward: Attackers capitalize on attention. With the FIFA World Cup 2026 attracting worldwide focus, cybercriminals are already setting up the infrastructure to take advantage. You need to prepare accordingly.

Read the full report from FortiGuard Labs provides a deep analysis of newly registered domains, malicious infrastructure, impersonation accounts, fake ticketing processes, job scams, malware activity, credential exposure, underground forum activity, and infrastructure reuse connected to tournament-themed campaigns.

Related Content

  1. NAS or Object Storage: Make the Best Backup Target Decision
  2. Disk Backup Targets Get Modern Makeover
  3. Disaster Recovery Journal
    Schedule & Archive

Recent Posts

BeyondTrust Extends Privileged Access Leadership with Release of NHI Governance for Every Non-Human and AI Identity

July 9, 2026

With Launch of CPS Segmentation, Cyolo Offers First Secure Connectivity Platform for Critical Infrastructure

July 9, 2026

Citrix Brings Unified Governance to LLM and Agentic AI traffic with NetScaler MCP Gateway Capabilities

July 9, 2026

Backblaze Publishes Q1 2026 Drive Stats: Reliability Improves as 92% of New Deployments Exceed 20TB

July 9, 2026

Keeper Security Surpasses $225M in ARR with Transformative Growth and is Emerging as the Market Standard for AI-Native Identity Security

July 9, 2026

Rubrik Joins Coalition for Health AI (CHAI) to Advance Responsible AI in HealthShare

July 8, 2026

Archives

  • July 2026 (20)
  • June 2026 (78)
  • May 2026 (67)
  • April 2026 (70)
  • March 2026 (89)
  • February 2026 (76)
  • January 2026 (61)
  • December 2025 (45)
  • November 2025 (58)
  • October 2025 (78)
  • September 2025 (65)
  • August 2025 (59)
  • July 2025 (70)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (90)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2026
    • Spring 2026

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal (DRJ) is the leading resource for business continuity, disaster recovery, crisis management, and risk professionals worldwide. With a global network of more than 138,000 practitioners, DRJ delivers essential insights through two annual conferences, a quarterly digital magazine, weekly webinars, and a rich library of online resources at www.drj.com. Our mission is to empower resilience professionals with the knowledge, tools, and connections they need to protect their organizations in a fast-changing world. Join our community by attending our events, subscribing to our publications, and following us on social media.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2026 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Fall 2026 | Resilience In Motion

    Leave your details below for a chance to win a free pass to DRJ Fall 2026 | Resilience In Motion. The winner will be announced on July 30. Join us for DRJ's 75th Conference!
    Enter Now