top of page

The dark side of World Cup 2026: A wave of high-tech crime besieges the football tournament

The 2026 FIFA World Cup officially kicked off on June 11, drawing the attention of millions of fans across the globe. However, behind the passionate festive atmosphere at the stadiums, other "matches" are also playing out with intense tension in cyberspace. The latest security reports show that international cybercrime organizations had quietly constructed, orchestrated, and deployed a massive phishing infrastructure months before the opening whistle blew.

Sophisticated phishing campaigns driven by AI technology and phishing emails

One of the biggest vulnerabilities today lies in the communication systems of the massive supply chain serving the World Cup, including airlines, hotels, media outlets, and service contractors. Security research indicates that more than one-third of FIFA's official partners lack strict email security configuration measures (Spoofed Email Blocking System (DMARC)). This allows attackers to easily send emails spoofing sponsors or logistics partners to execute fraudulent transactions amidst the fast-paced timeline of the tournament.

Furthermore, a wave of hunting for and registering "lookalike" domains related to the World Cup has exploded. Experts have recorded:

  • More than 1,122 newly registered domains containing the phrases “World” and “Cup” with suspicious signs.

  • More than 600 domains intentionally misspell the FIFA homepage (typosquat).

  • Notably, a Chinese-speaking cybercrime group has conducted large-scale clones of the official FIFA website interface across approximately 300 different domains to steal user account credentials.

The major differentiator of this year's tournament is the emergence of AI. Threat actors can now use generative AI to automatically produce and distribute thousands of deceptive links via email and text messages (phishing and smishing) with highly natural wording, making them extremely difficult for ordinary users to detect.

A "matrix" of fake online stores and travel websites

As the demand for ticket hunting and hotel bookings surged, "ghost" websites began mushrooming. This peaked around March and April, two months before opening day, when registrations for fake travel websites spiked, accounting for over 34% of all detected samples within the past year. Among these, hotel and accommodation brands were the most frequently impersonated (accounting for 56%), followed by travel agencies (27%). Most of these sites choose to use cheap domain extensions like .top to easily maintain their infrastructure despite takedown orders from authorities.

Alongside travel websites, fake World Cup souvenir stores are equally sophisticated. Instead of just stealing credit card information like before, these stores configure legitimate merchant accounts to directly charge victims for orders that are never delivered. A fraudulent campaign detected in April and May operated a network of 33 domains linked to 2,500 online advertisements. When one domain is blocked, they immediately rotate to another while keeping the underlying payment infrastructure hidden behind the scenes.

More dangerously, cybercriminals are also employing a tactic of compromising legitimate websites with high Google rankings, then injecting malicious code to automatically redirect users to phishing pages. In this way, the fraudulent website does not need to appear on search engines but still traps a massive volume of traffic from fans. Other forms of scamming are so sophisticated that they trick users into integrating their bank cards into digital wallets installed on the attackers' own devices.

Instead of just stealing credit card information like before, these stores configure legitimate merchant accounts to directly charge victims for orders that are never delivered.
Instead of just stealing credit card information like before, these stores configure legitimate merchant accounts to directly charge victims for orders that are never delivered.

Explosion of betting apps and social media traps

The sports betting sector has also become a "gold mine" for scam groups. According to a survey of mobile app stores, the number of fake betting applications impersonating major bookmakers skyrocketed 60-fold during April and May. Within a short period, a few fraudulent developer accounts repeatedly launched multiple apps onto the Google Play store that simultaneously counterfeited various betting brands.

Beyond mobile apps, the social media platform Telegram has seen a surge of Russian-language channels claiming to be "match-prediction experts." Their tactic is to divide subscribers into two groups and provide contradictory predictions. This way, half of the players always win and continue to trustfully deposit more money through referral links. The fraudsters simply sit back and pocket lucrative commission fees from the victims' deposits on fraudulent betting platforms.

The vortex of ransomware and cyber espionage risks

It is not just fans; football organizations are also squarely in the crosshairs. The dark web market is currently flooded with compromised personal accounts related to FIFA up for sale, serving as tools for notorious criminal groups like ShinyHunters or splinters of Scattered Spider to conduct social engineering attacks (psychological manipulation, account hijacking...).

Within the past few months, several international football organizations have suffered severe cyberattacks resulting in data loss, including major clubs such as Olympique de Marseille, AFC Ajax, and Al Nassr. Most notable was the attack by the ShinyHunters group on the Asian Football Confederation (AFC) and Al Nassr FC, which leaked and put up for sale sensitive personal data, including passport scans and contracts… of over 150,000 players on hacker forums. Numerous other football federations, such as those of Germany, Oman, Argentina, or the Confederation of African Football, were also indirectly affected by ransomware attacks executed via third-party partners.

On the other hand, because the event gathers a large number of high-ranking government officials, national delegations, and major corporate executives, World Cup 2026 also faces cyber espionage risks from state-sponsored hacking groups from nations such as Russia, China, and Iran. The objective of these groups is to gather intelligence by attacking the systems of airlines, telecommunications providers, hotels, and tournament logistics units.

The 2026 World Cup is a pinnacle sporting event, but it is concurrently a "highly lucrative playground" that cybercriminals have meticulously prepared for well in advance. Rushed transactions, anxious mentalities to find tickets and secure accommodations, or downloading apps from unknown sources during this period represent the greatest opportunities for malicious actors to exploit. For both enterprises and fans alike, tightening authentication measures and maintaining a high level of vigilance is the sole shield to protect oneself against this wave of malicious technology.

References: The Hacker News, Threats to the 2026 FIFA World Cup

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page