Super Bowl LX at Levi’s Stadium is being supported by a large, multi-agency security operation, with the NFL and the U.S. Department of Homeland Security coordinating extensive federal, state, and local participation under a Tier 1 Special Event Assessment Rating (SEAR) designation. Planning has been underway for roughly 18 months, and officials described a broad security footprint extending beyond game day to surrounding events in the San Francisco Bay Area.
From a cyber perspective, a threat assessment reported no specific, credible cyber threats currently targeting Super Bowl LX, but warned that high-visibility events commonly drive opportunistic cybercrime aimed at fans and attendees—particularly phishing, scams, malware, and payment-card fraud tied to tickets, travel, and event-related promotions. The assessment also pointed to prior sports-related incidents (e.g., a team online store compromise and a ransomware attack on an NFL team in a prior Super Bowl lead-up) as context for why organizers and partners should expect social engineering and impersonation attempts even absent indications of targeted attacks on league infrastructure.

Get the infrastructure and lures behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Super Bowl LX was set to take place on February 8, 2026, at Levi’s Stadium in Santa Clara, drawing heightened cyber, physical, and public-safety preparations because of the event’s scale and profile.
Airspace protections were put in place around Levi’s Stadium, including temporary flight restrictions and an FAA/FBI-designated 'No Drone Zone' for the Super Bowl.
Officials coordinated a large security operation for Super Bowl LX across nine Bay Area counties, with participation from agencies including DHS, Secret Service, ATF, CBP, CISA, TSA, and regional emergency services.
Analysts observed online sentiment and protest-related chatter tied to alleged ICE activity and controversy around performers, including plans for a protest near the stadium on game day, but no calls for violence were identified.
Flashpoint said it had not observed any specific cyber threats targeting Super Bowl LX, while warning that opportunistic phishing, scams, malware, fraud, impersonation, and social engineering could still target attendees and related populations.
Super Bowl LX received a DHS tier one Special Event Assessment Rating, also described as SEAR-1, triggering significant federal support and layered security preparations.
Planning for Super Bowl LX security began about 18 months before the event, involving the NFL and more than 35 state, local, and federal agencies across the San Francisco Bay Area.
The Green Bay Packers' online store was compromised in 2024, another historical sports-related cyber incident referenced in threat assessments for Super Bowl LX.
The San Francisco 49ers were hit by a BlackByte ransomware attack ahead of Super Bowl LVI, later cited as a historical example of sports-related cyber risk relevant to major events like the Super Bowl.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.