logo

Thousands of Fake FIFA Domains Target World Cup Fans

ID: 7f26ca0a-c1b9-588a-bd34-3a9446800a91

STIX ID: report--7f26ca0a-c1b9-588a-bd34-3a9446800a91

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

Group-IB analysis found more than 4,300 fraudulent domains impersonating FIFA, run by at least four operators including a Chinese-speaking actor called Ghost Stadium that uses cloned fifa.com pages promoted via paid Facebook ads; campaigns include phishing kits, PhaaS offerings and infostealer infections (Vidar, Lumma) that have harvested ~2,500 FIFA credentials, with monetization via crypto on-ramps and estimated losses from ticket fraud into the millions or higher. The report recommends buying only from fifa.com, enabling MFA, monitoring dormant domains for activation, and pursuing registrar-level takedowns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.