FortiGuard Labs has identified an active cybercriminal ecosystem targeting the FIFA World Cup 2026, which begins June 11. From January to May 2026, over 13,000 FIFA-themed domains were registered, with roughly 8.8% flagged as malicious or suspicious. Threat categories include fake ticketing sites, social media impersonation (1,700+ accounts, mostly on Facebook/Instagram), malicious betting and streaming APKs, fake job postings used for credential harvesting, and stealer malware logs containing 270,000+ fan credentials and 260+ FIFA employee credentials. Attackers are exploiting fan urgency around ticket scarcity, leveraging legitimate cloud services like Render for phishing infrastructure, and coordinating campaigns across multiple impersonation domains sharing the same Google Analytics ID. Security teams are advised to monitor for lookalike domains, brand impersonation, and credential leaks, while users should stick to official channels and avoid third-party app downloads.

7m read timeFrom feeds.fortinet.com
Post cover image
Table of contents
A Fast-Growing Threat LandscapeFake Ticketing Remains One of the Highest-Risk LuresSocial Media Impersonation Expands the Attack SurfaceMalware Is Also Part of the Tournament Threat LandscapeFake Job Postings Target People Looking for OpportunityCredential Exposure Raises the StakesWhat You Should Do Now
162 Impressions