Thousands of Fake FIFA Domains Target World Cup Fans
ID: 7f26ca0a-c1b9-588a-bd34-3a9446800a91
STIX ID: report--7f26ca0a-c1b9-588a-bd34-3a9446800a91
Feed Name: Infosecurity Magazine (News)
Group-IB analysis found more than 4,300 fraudulent domains impersonating FIFA, run by at least four operators including a Chinese-speaking actor called Ghost Stadium that uses cloned fifa.com pages promoted via paid Facebook ads; campaigns include phishing kits, PhaaS offerings and infostealer infections (Vidar, Lumma) that have harvested ~2,500 FIFA credentials, with monetization via crypto on-ramps and estimated losses from ticket fraud into the millions or higher. The report recommends buying only from fifa.com, enabling MFA, monitoring dormant domains for activation, and pursuing registrar-level takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
