logo

FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

ID: c1b7f4a2-9ea2-599c-9292-e9b4a2e485b4

STIX ID: report--c1b7f4a2-9ea2-599c-9292-e9b4a2e485b4

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: [email protected] (The Hacker News)

...
...

Researchers and the FBI report a large, active fraud campaign targeting World Cup 2026 fans: thousands of lookalike FIFA domains and phishing sites (including a cluster dubbed GHOST STADIUM), fake ticket and merchandise shops, and malicious streaming apps that install Android banking trojans (Massiv, Perseus). Credential-stealing families (Vidar, LummaC2, RedLine), reuse of ad tracking codes, crypto-only payment asks, and parked domains ready to activate indicate a high-scale operation with measurable financial impact; recommended mitigations include buying only via fifa.com, enabling MFA, avoiding sideloaded streaming apps that request accessibility access, and monitoring for FIFA-themed IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.