logo

World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat

ID: 8ffe1637-dd15-5dd9-8c6c-6d97799041e7

STIX ID: report--8ffe1637-dd15-5dd9-8c6c-6d97799041e7

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

Zimperium documents three active, sophisticated phishing campaigns exploiting FIFA World Cup 2026 demand: (1) production-grade typosquatted ticket sites that harvest credentials and payment data, (2) a multi-language retail phishing (“RetailPhish”) propagated via WhatsApp and hidden behind Cloudflare and a unified registrar account, and (3) recruitment-themed AiTM platforms targeting corporate Google Workspace accounts to intercept MFA and perform session hijack — all posing significant mobile-to-enterprise risk with identified domains, infrastructure, and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.