Vesal Security reported a large-scale automated fraud operation targeting FIFA World Cup 2026 ticket draws from May 2024 through July 2026. The assessment attributes the creation of 1,373,231 FIFA accounts and 710,521 successful draw applications to two automation providers, Firefly and ConsolDes, with six services allegedly offering account creation, draw registration, password resets, and bypasses for anti-bot controls including DataDome and Akamai.
The operators allegedly resold successful allocations and tickets on online forums, while using the same tooling against co-sponsor promotions and a European football federation's ticket allocations. Organizations operating high-demand ticketing or promotional systems should review account-creation, draw-entry, and resale-abuse telemetry, and strengthen controls against automated registration and anti-bot evasion; the report's claims should be treated cautiously because its stated fact-verification score was 40/100 and it supplied no extractable indicators of compromise.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
On July 31, 2026, Vesal Security published an assessment attributing 1,373,231 FIFA account creations and 710,521 successful ticket-draw applications to Firefly and ConsolDes. The assessment also reported ticket selections and tickets being offered for resale on secondary forums.
From July 7, 2026, Coalpit reportedly offered retail-account creation under a World Cup-related pretext.
From November 3, 2025, Hades reportedly offered browser- and request-based account creation capabilities with Akamai handling.
From September 10, 2025, Ironwood and Palewater reportedly offered anti-bot bypass capabilities against fifa.com. Ironwood's capabilities targeted DataDome and Akamai protections.
From September 30, 2024, Firefly reportedly offered FIFA account creation and ticket-draw entry capabilities, as well as functionality targeting sponsor promotions.
From September 2, 2024, ConsolDes reportedly offered FIFA account creation, repeated ticket-draw entry, and password-reset capabilities.
The first version of a tool linked to the FIFA ticketing automation campaign was published in September 2024, approximately 21 months before the tournament.
Vesal Security's assessment describes a fraudulent automation operation targeting FIFA World Cup 2026 ticketing as active from May 2024 through July 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.