logo

GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans With 300+ Fake Domains

ID: d4bf3b85-2cde-51fe-9a1d-088cb23a77be

STIX ID: report--d4bf3b85-2cde-51fe-9a1d-088cb23a77be

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Tushar Subhra Dutta

...
...

Researchers uncovered a coordinated, high-scale fraud operation (GHOST STADIUM) exploiting FIFA World Cup 2026 ticket demand: a React-based phishing kit clones FIFA’s SSO (using a real client_id) across 300+ domains and 3,500+ impersonating sites, while Vidar and Lumma infostealers harvest browser credentials and session tokens; the report provides extensive IoCs (domains, IPs, Meta Pixel IDs, payment gateways) and recommends monitoring, takedown, MFA, and user caution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.