The FBI is warning that forward of the 2026 World Cup, pretend web sites impersonating FIFA are stealing private and monetary data, promoting pretend tickets and hospitality packages, and selling different scams associated to the event.
Attackers have arrange tons of of phishing websites as a world soccer event can be held in the US, Canada, and Mexico from June eleventh to July nineteenth.
In line with the FBI’s public service announcement, the pretend domains impersonate the official fifa.com, however depend on small spelling adjustments that customers simply miss, comparable to fifa(.)com, use alternate top-level domains (comparable to .org, .xyz, .dwell, and .sale), and in addition use pretend employment portals comparable to “jobs-fifa(.)com” and “fifa-hiring(.)com.”
The company notes that many fraudulent web sites gather varied sorts of information from guests, together with names, addresses, e-mail addresses, cellphone numbers, and banking and cost particulars, which can be utilized to create fraudulent accounts, commit id theft, or commit monetary fraud.
The size of those campaigns can be mirrored in a report by cybersecurity companies Group-IB and Bitdefender, whose researchers noticed World Cup-related malvertising campaigns promoted by means of Google Search, Fb Adverts, Telegram, and WhatsApp.
Group-IB researchers have discovered {that a} large-scale operation by Chinese language attackers, tracked as Ghost Stadium, is utilizing greater than 300 phishing websites which might be clones of the true FIFA portal for premium ticket fraud.
.jpg)
Supply: Group-IB
Beginning in February, Bitdefender noticed scams surrounding the World Cup model, together with gives for pretend merchandise, kits and collectibles, streaming providers, and Panini stickers, concentrating on customers in the UK, Portugal, Spain, Algeria, United States, Canada, Mexico, Brazil, Germany, and Australia.

Supply: Bitdefender
Learn how to shield
As public curiosity within the World Cup will increase, cybercriminals use varied traps to create fraudulent on-line portals geared toward promoting pretend merchandise and stealing cash and consumer information.
Followers can keep away from these dangers by following easy suggestions from the FBI.
- Manually sort “fifa.com” into your browser
- Keep away from sponsored search adverts or use an advert blocker
- Make certain the URL ends in .com
- Utilizing FIFA official web site bookmarks
- Keep away from suspicious hyperlinks despatched through Direct Messages
- By no means enter delicate information except the location is verified as real
Customers are inspired to report incidents to the FBI’s Web Crime Criticism Middle (IC3) and embody particulars such because the pretend area used, interplay historical past, and cost data in order that authorities can take motion in opposition to fraudulent portals.
Automated penetration testing instruments supply actual worth, however they had been constructed to reply one query: Can an attacker get by means of your community? They aren’t constructed to check whether or not controls block threats, detection guidelines fireplace, or cloud configurations are preserved.
This information describes six surfaces that it is best to really look at.
Obtain now
