Cybercriminals launched multiple parallel fraud campaigns around the 2026 FIFA World Cup, using fake merchandise stores, cloned FIFA portals, bogus ticketing and betting sites, QR-code and SMS lures, and cryptocurrency scams to steal credentials, payment card data, and personal information. Researchers reported more than 13,000 FIFA-themed domains registered between January and May 2026, with a notable share deemed malicious or suspicious, while one purchase-scam cluster alone used about 33 domains and roughly 2,500 online ads to impersonate major sports brands and push victims into WhatsApp-based social-engineering funnels. Analysts also identified persistent portal-cloning kits with mirrored SSO flows and hundreds of static HTML files, as well as rapidly rotated betting and traffic-monetization domains that redirected users through affiliate-tracked overlays and iframes.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Netskope said that over the course of the 2026 FIFA World Cup it detected and blocked more than 28,000 World Cup-themed threats across more than 1,000 organizations worldwide. The company also reported that user attempts to access malicious World Cup-themed content peaked at nearly six times the pre-tournament average, spanning phishing, fake streaming sites, and malware delivery.
The exposed FIFA Agent Platform access-control issue was reportedly remediated within hours after discovery, limiting the duration of the broadcast infrastructure exposure.
A critical broken access control vulnerability in FIFA's Agent Platform reportedly exposed streaming management, live camera controls, RTMP ingest links and stream keys, match data, and commentator systems.
The report describes a free Web3 phishing kit branded around a 'World Cup Coin' that supports 17 cryptocurrency wallets and exfiltrates seed phrases or private keys via Telegram or email, enabling irreversible wallet theft.
A separate World Cup-related purchase scam cluster reportedly operated about 33 domains tied to roughly 2,500 online advertisements, impersonating major sports brands and using WhatsApp-based social engineering to collect PII and payment card data.
The reporting states that over 13,000 FIFA-themed domains were registered between January and May 2026, with a meaningful portion identified as malicious or suspicious as scammers prepared World Cup-themed fraud infrastructure.
Researchers documented multiple parallel FIFA World Cup 2026 fraud campaigns, including fraudulent merchandise storefronts, cloned FIFA portal infrastructure harvesting credentials and payment data, and ticketing or sports-betting schemes redirecting users to affiliate platforms.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 63 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
netskope.com
Open sourcemalware.news
Open sourcemalware.news
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.