A phishing and fraud operation impersonating FIFA ahead of the 2026 World Cup has expanded far beyond initial estimates, growing from 79 known domains on 14 IPs to at least 222 domains spread across 203 unique IP addresses. The sites mimic official FIFA branding, copy page structure, and reuse images and icons from the legitimate website to lure fans through typosquatted and lookalike domains such as vww-fifa[.]com and fifa[.]sale. Researchers said the infrastructure is designed to steal credentials and payment data, collect money for fake tickets or merchandise, and potentially compromise legitimate FIFA accounts so real tickets can be stolen and resold.
The latest investigation found the activity is not a single centralized campaign but at least four distinct operator clusters sharing scam templates while differing in hosting, registration patterns, and WHOIS fingerprints. Analysts linked parts of the infrastructure to repurposed aged .shop domains, a smaller .cn cluster, and domains using the fake registrant organization "888 World Cup Management Co Ltd." Most of the sites sit behind Cloudflare, which independently flagged several as phishing, and 206 of the 222 domains were still active at the time of reporting, with registrations accelerating in April. Researchers urged broader detection beyond obvious FIFA-themed names and called for registrar-level disruption, particularly involving GNAME.COM and GoDaddy.

Get the infrastructure and lures behind it.
19 events from the most recent confirmed update back to the earliest known activity.
Gurucul reported a high-severity phishing campaign using 2026 FIFA World Cup 'Champion Reward' survey emails to steal personally identifiable information and full payment card details. The operation used traffic filtering to evade sandboxes and non-U.S. visitors, and exfiltrated stolen data to gocellbel.com/api/orders, indicating a card-theft and identity-fraud monetization scheme.
KnowBe4 ThreatLabs said FIFA World Cup 2026 phishing activity tracked from early April through 2026-06-22 did not decline after kickoff but instead rose to a 22-fold mid-tournament escalation. The report also said attackers increasingly favored FIFA-branded display-name spoofing, reply-back scams, and redirect chains over traditional domain-based lures.
Cyble Research and Intelligence Labs reported a coordinated FIFA World Cup 2026 fraud operation it calls Operation FanTrap, identifying nearly 4,000 FIFA-themed domains since May 2026 used for phishing, fake ticket and VIP sales, pirate streaming lures, and brand impersonation. The report said attackers targeted Chinese-speaking, Korean, and Latin American audiences and moved victims from public sites and social platforms into Telegram and WhatsApp channels for payment fraud, credential theft, and identity harvesting.
Confiant reported a surge in 2026 FIFA World Cup scam and malvertising activity in the weeks before kickoff, including fake ticket portals, counterfeit merchandise stores, Panini-themed impersonation sites, and deepfake gambling ads. The report said agencies including the FBI, RCMP, and Canadian Anti-Fraud Centre warned about spoofed domains and related fraud, while attackers used cloaking, typosquatted domains, fake Google Play pages, and sideloaded APK lures to target fans.
TRM Labs reported that scammers are already exploiting 2026 FIFA World Cup interest through crypto-themed fraud, including fake ticketing sites, fixed-match betting schemes, scam-kit sales, and fan-branded meme coin promotions. The company said it identified three live World Cup-related scam operations tied to four crypto addresses and observed use of cross-chain bridges and custodial exchange accounts to move proceeds.
CloudSEK reported a large-scale FIFA World Cup 2026 ticket fraud operation using typosquatted domains, cloned FIFA pages, and a Chinese-language multi-tenant backend at admin-zone[.]tbpay[.]uk. The company said the infrastructure operated as a real-time man-in-the-middle framework that captured payment card data and relayed OTP codes to bypass SMS-based 2FA, and assessed with moderate-high confidence that the operators were PRC-based.
Arctic Wolf reported that by June 2026 cybercriminals had built a mobile-first 2026 FIFA World Cup scam ecosystem using more than 10,000 themed domains observed since January, fake ticket and careers sites, QR-code phishing, and malware-laced apps and files. The company also identified a real-time adversary-in-the-middle phishing kit that could capture and replay MFA codes against Google, expanding the story beyond domain spoofing into MFA-bypass and organization-targeted attacks.
Meta said it disrupted a scam network that used FIFA World Cup branding to funnel users to fraudulent gambling sites. This is a new response action by a major platform against World Cup-themed cyber fraud infrastructure.
The FBI said scammers spoofing FIFA websites were also targeting job seekers with employment-themed domains such as fifa-hr[.]com, jobs-fifa[.]com, fifa-hiring[.]com, and fifaworldcup-careers[.]com. The bureau said it had flagged 36 suspicious domains and warned the number of spoofed sites would likely continue growing through the tournament period.
Corporation Service Co. reported that more than 65,590 third-party domains containing the term 'FIFA' were registered from January 2022 through April 2026, with none registered by FIFA itself. The report also highlighted 163 'FIFA tickets' domains as especially likely to be used for fraud around ticket-sale periods.
Group-IB reported that since August 2025 it had identified more than 4,300 fraudulent domains impersonating FIFA as part of a broader World Cup fraud ecosystem. The company said the activity included multiple threat actor categories, estimated ticket-fraud losses from the campaign at $71 million to $474 million, and found 2,513 FIFA credential pairs circulating on dark-web markets.
The FBI warned that cybercriminals were spoofing FIFA websites ahead of the 2026 World Cup using typosquatted and lookalike domains to steal personal and financial information and sell counterfeit tickets and hospitality packages. The bureau also published a list of spoofed domains and consumer safety guidance, warning that more fraudulent sites were likely to appear before the tournament.
Group-IB reported that more than 300 domains were tied to a coordinated World Cup phishing campaign and attributed central control to a Chinese-speaking financially motivated operator it tracks as GHOST STADIUM. The report also described six fraud schemes, use of a custom phishing kit, Facebook ad traffic, and overlap with Vidar and Lumma infostealer activity affecting FIFA-related credentials.
Gen Digital researchers documented a recruitment-themed phishing campaign using fake FIFA hiring pages such as fifahiring[.]com, careers-fifahiring[.]com, and fifajobs[.]com to steal business credentials through fake interview and sign-in workflows. The report said the infrastructure appeared newly created on 2026-05-23, used Vercel and Render hosting, and was part of a broader reusable kit also impersonating other major brands.
At the time of the expanded report, 206 of the 222 identified domains remained active, with several independently flagged as phishing by Cloudflare, confirming the campaign was ongoing.
A follow-up Flare investigation found the infrastructure had grown to at least 222 domains across 203 unique IPs and assessed that it was not a single centralized operation but at least four distinct clusters sharing scam templates.
Flare reported a phishing campaign impersonating FIFA ahead of the 2026 World Cup, identifying at least 79 fraudulent websites using typosquatting and lookalike domains to steal credentials, payment data, and money for fake tickets or merchandise.
Between April 1 and April 17, 2026, researchers observed 52 additional domains registered as the campaign accelerated, indicating continued growth of the fraud infrastructure.
Group-IB said the FIFA-themed fraud operation it tracks as GHOST STADIUM was first observed in November 2025. The campaign used pixel-perfect FIFA clones to steal credentials and payment details from fans seeking World Cup tickets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 300 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
41 references tracked. Mallory keeps watching after this page renders.
dispatch.thorcollective.com
Open sourceblog.knowbe4.com
Open sourcecommunity.gurucul.com
Open sourceblog.alphahunt.io
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.