Malware/Ransomware
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
Cyber RTJune 5, 20263 min read

Security researchers and the FBI are warning of FIFA-themed fraud targeting World Cup 2026 fans. Scams include thousands of fake FIFA domains, phishing sites, and banking malware in streaming apps. Group-IB identified a Chinese operation, GHOST STADIUM, behind 300 cloned FIFA sites. Fraudsters exploit ticket scarcity and fan anxiety, with potential losses reaching billions. Fans should buy tickets only from fifa.com, avoid crypto payments, and be cautious of streaming apps requesting accessibility access.
Security researchers and the FBI have issued warnings about a surge in FIFA-themed fraud targeting fans of the World Cup 2026, just days before the tournament's kickoff on June 11. Reports highlight thousands of fraudulent FIFA domains, banking malware hidden in pirate streaming apps, and operations that mimic FIFA's login page to hijack real accounts. With over six million fans expected across 16 cities in North America and a high demand for tickets, the environment is ripe for fraudsters to exploit anxious fans and the fast-moving money associated with the event.
Group-IB, a cybersecurity firm, has identified over 4,300 fraudulent FIFA domains since August 2025, with a significant operation named GHOST STADIUM at the center. This group, believed to be Chinese-speaking, uses a phishing kit across more than 300 sites, creating near-perfect replicas of FIFA's official website. These fake sites even mimic FIFA's single sign-on login system, tricking users into providing their credentials, which allows attackers to lock victims out of their accounts and resell any associated tickets.
The fraudulent sites primarily attract traffic through Facebook ads and links on platforms like Telegram and WhatsApp. They offer multiple payment methods, including direct card entry and cryptocurrency, the latter being a clear indicator of a scam since FIFA does not accept crypto payments. Group-IB estimates that losses from premium and hospitality ticket fraud could range from $71 million to $474 million, with the entire campaign potentially reaching billions.
Other cybersecurity firms, like FortiGuard Labs, have also reported a significant number of World Cup-themed domains, with a portion deemed malicious or suspicious. The FBI has listed numerous fake FIFA domains and warns of more to come. Beyond ticket fraud, scams include counterfeit merchandise, fake streaming sites that install malware, and bogus betting sites that collect personal data for identity theft.
A particular threat comes from banking malware hidden in unofficial streaming apps, which are expected to proliferate during the World Cup. These apps, often masquerading as popular streaming services, contain Android banking trojans like Massiv and Perseus. Once installed, they can take over a user's phone, overlay fake bank login screens, and intercept security codes, posing a significant risk to fans seeking free match streams.
Social media platforms are also rife with scams, with numerous fake FIFA accounts and ad campaigns pushing counterfeit merchandise and phishing pages. Stolen FIFA logins are already circulating, and open Wi-Fi networks in host cities present additional risks, as they can be exploited by rogue hotspots to intercept user data.
To protect themselves, fans are advised to purchase tickets only through the official FIFA website, enable multi-factor authentication, and avoid any seller requesting cryptocurrency payments. On Android devices, users should be wary of streaming apps asking for unnecessary permissions. Security teams are urged to monitor for new fraudulent domains and prepare for potential spikes in fraud-related activities during the tournament.
In response, Meta is implementing measures to warn users searching for FIFA tickets on Facebook and has collaborated with Visa to dismantle networks linked to fake World Cup sites. The FBI encourages victims of scams to report incidents through its Internet Crime Complaint Center (IC3). Despite these efforts, the potential for further fraud remains high, with thousands of fraudulent domains still inactive but ready to exploit the peak period of interest in the World Cup.


