Palo Alto Networks Unit 42 warned that the 2026 FIFA World Cup will present an unusually broad cyberattack surface because the tournament spans 16 host cities across the United States, Canada, and Mexico and will depend on temporary event networks layered onto existing stadium and municipal systems. The report said likely targets extend beyond venues to transit, power, water, airports, emergency services, hotels, suppliers, ticketing platforms, and official digital services, creating multiple paths for disruptive intrusions during the competition window.
The assessment identified Iran-linked actors, including Handala Hack Team and CyberAv3ngers, as notable risks for destructive activity and OT/PLC targeting, while NoName057(16) was highlighted for politically timed DDoS campaigns. Unit 42 said financially motivated cybercrime is also likely to focus on hospitality and fan-facing services through ransomware and fraud, and it urged organizers and host-city partners to strengthen multi-jurisdiction coordination, harden OT environments, audit suppliers, prepare DDoS defenses, run destructive-malware exercises, and tighten identity and help-desk controls before kickoff.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
A Unit 42 report assessed the 2026 FIFA World Cup as a highly exposed cyber target due to its 16 host cities across the United States, Canada, and Mexico, temporary tournament networks, and dependence on municipal infrastructure. The report identified likely threats including disruptive intrusions, cyber fraud, ransomware, and politically motivated DDoS and hack-and-leak operations, and recommended defensive preparations before the tournament window.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.