World Cup 2026 Phishing Infrastructure Is Already Stood Up
Lookalike FIFA domains, trojanized streaming apps, and credential harvesters are live weeks before kickoff. The pattern is familiar; the scale isn't.

Kickoff is June 11. The phishing kits went live earlier.
Researchers tracking World Cup 2026 fraud are flagging thousands of FIFA-themed lookalike domains, banking trojans bundled into pirate streaming apps, and at least one credential harvester that mirrors FIFA's real login page closely enough to take over legitimate ticketing accounts. The FBI has separately warned fans to expect the usual buffet of ticket resale scams, fake hospitality packages, and bogus travel sites.
In practice, this is the same playbook attackers run for every Olympics, every Super Bowl, every Eurovision. What's different is volume. A tournament hosted across the US, Mexico and Canada means three jurisdictions, three payment ecosystems, and roughly a year of pre-event search traffic for attackers to monetize. The bulk-registered domains we're seeing now were almost certainly squatted months ago.
The failure mode here is mostly identity, not malware.
Fans land on a domain that looks like a regional FIFA portal, enter the credentials they used on the real ticketing site, and the operator either resells the account or drains stored payment methods. If you reused that password anywhere else, the blast radius is wherever your password manager refused to autofill. Which is the tell, by the way — if your manager won't fill it, the domain isn't what you think it is.
The streaming-side problem is uglier. Pirate apps promising free match coverage have historically shipped with banker overlays targeting Android — think Anubis, Hydra, and the newer Coper variants. Sideloading an APK to watch a group-stage match is how people end up with their bank app's screen quietly captured and 2FA prompts intercepted. iOS users aren't immune either; the equivalent vector is a profile install masquerading as a streaming "helper."
A few things worth doing before June:
- Buy tickets only through FIFA's official ticketing portal and verify the URL by hand, not by clicking ads. Google's sponsored results have been a reliable phishing vector all year.
- Treat any "free stream" app outside the official app stores as hostile. If it asks for accessibility permissions on Android, it is malware. There is no other reading.
- Put a unique password on your FIFA account and turn on whatever MFA option they're offering. SMS is bad but not zero.
- Watch for refund and chargeback scams after the tournament too. The long tail of these events runs into 2027.
One thing the post-mortem will say: the abuse infrastructure was visible in passive DNS for months, and nobody with takedown authority moved fast enough.
Operational takeaway: if your fraud team isn't already ingesting FIFA-themed domain registrations into your phishing feeds, you're going to read about your customers in the news.



