By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Cybercriminals Exploit FIFA 2026 Hype with Lookalike Domains and Account Takeovers
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Cybercriminals Exploit FIFA 2026 Hype with Lookalike Domains and Account Takeovers

A coordinated phishing campaign using over 300 cloned FIFA sites is targeting fans ahead of the 2026 World Cup, aiming to steal login credentials and resell tickets.

CSBadmin
Last updated: June 7, 2026 1:33 am
CSBadmin
2 Min Read
Share
SHARE

The Phishing Campaign Behind the Scams

With the FIFA World Cup 2026 set to kick off on June 11, security researchers and the FBI are warning about a surge in targeted fraud. Group-IB has identified over 4,300 fraudulent domains registered since August 2025, with a single group, referred to as GHOST STADIUM, operating a coordinated campaign across more than 300 of these sites. The operation uses a highly convincing phishing kit that copies FIFA’s official login page, including a cloned single sign-on interface that replicates genuine elements like the PingIdentity client ID. The fake pages even load images directly from FIFA’s servers to evade detection tools. Victims are asked to reset their passwords, which allows attackers to lock users out of their accounts and resell any tickets associated with them.

Contents
The Phishing Campaign Behind the ScamsImpact and Scope of the Threat

Impact and Scope of the Threat

The scale of the opportunity for fraudsters is enormous, with over 150 million ticket requests submitted for the tournament, leaving it roughly 30 times oversubscribed. The phishing campaign drives traffic primarily through Facebook ads, Telegram, WhatsApp, and search results. Once on the fake site, the payment process offers five different methods, including direct credit card entry, money transfer apps like Chime and Nequi, and a cryptocurrency conversion option. The crypto option is a strong red flag, as FIFA’s official ticketing system never accepts cryptocurrency, making it harder for victims to recover their funds after a transaction.

Source: The Hacker News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverGroup-IBWorld Cup
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Active Attacks Target Cisco SD-WAN Manager Flaw With No Available Fix
Next Article Fake Security Tool Sites Deliver Stealth Malware to Researchers

Trending

BraZetsu turns hacked Windows machines into inventory for access bazaar
September 5, 2026
GPT-6 Astra launch pairs perfect ExploitBench run with stricter guardrails
September 5, 2026
PostGREShell bug turns lowly PostgreSQL backup roles into superusers
September 5, 2026
Thomson Reuters court case files breach may touch sealed records and SSNs
September 5, 2026
Cisco Nexus 9000 switches leave two TCP ports open to root access
September 5, 2026

Related Stories

CSBadmin

Attackers Exploit Cisco Unified CM Flaw After Public PoC Exposes Path to Root Access

CSBadmin

AmnesiaStealer trades keychain dumps for live macOS browser hijacks

CSBadmin

29 Million Secrets Exposed in 2025: The AI Agent Credential Crisis

CSBadmin

Apollo confirms cloud intrusion as BlackFile spree widens

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.