The images in this article were generated with artificial intelligence. How we publish
As the FIFA 2026 World Cup approaches, the warnings of cyber security agencies and companies make it clear that the event will attract as much attention from fans as from digital criminals: the FBI has published a public notice about hundreds of fraudulent domains that mimic official portals to steal data, sell false tickets and execute other tournament-related fraud ( see FBI / IC3 PSA). The criminal operation takes advantage of simple and effective techniques such as typosquatting, alternative TLDs and cloned pages, along with maldumping campaigns in search engines and social networks.
The attackers use minimum variations of the legitimate domain - for example by replacing letters or using confused characters - and terminations such as .xyz, .sala or .org to appear authentic. There are also false places that promise jobs, hospitality packages or premium ticket resales; some actors have deployed hundreds of identical URLs to amplify the scam. The expected result: committed personal and financial data, usurped identity and fraudulent charges to cards or bank accounts.

Beyond the direct loss of money, the consequences include the creation of false accounts in the name of the victims, the sale of information in clandestine markets and the use of credentials for subsequent movements such as social media fraud or access to corporate accounts. Campaigns observed by firms such as Bitdefender and public reports also show that distribution channels range from paid ads on Google and Facebook to messages on Telegram and WhatsApp, which complicates risk visibility. Bitdefender documents these patterns a useful reading to understand how deception is promoted.
For fans planning to buy tickets, packages or souvenirs, recommendation number one is simplicity: avoid clicking on unexpected ads or links and manually type the official address (fafa.com) or use verified markers. The scammers have the confidence that the sponsored ads generate and many users do not carefully examine the full URL or the spelling of the domain.
Practical techniques to verify a site include checking that the URL ends in .com when it comes to the official domain, looking at the TLS certificate (by clicking on the browser lock to see which entity was issued) and using public tools such as reputation search engines or URL analysis services before entering sensitive data. An HTTPS chain and a lock do not guarantee a web is legitimate: only the connection is encrypted, and modern clones usually use valid certificates.
In payments, prioritize methods that offer protection and dispute capacity: single-use virtual cards, walkways such as PayPal or banking services that allow to cancel transactions quickly. Activate movement alerts in your account and limit the information you share (do not enter social security numbers, complete bank credentials or document photos) unless the platform is verified and necessary for a legitimate transaction.
If you receive job offers related to FIFA or the World Cup, distrust if you are asked for financial data in advance or use messaging applications to process contracts. Legitimate recruitment processes rarely request money or early-stage bank data from unofficial channels; confirm vacancies by consulting only the official pages of the organiser or verified corporate channels.

In case of suspicion or fraud, keep evidence (screenshots, URLs, e-mails and payment vouchers) and report the incident as soon as possible: contact your bank to block or reverse charges, change affected passwords and file a complaint on the FBI / IC3 platform if it is in the USA. EU or the competent body in your country. Reporting domains and ads also helps to dismount campaigns: the more data the victims and hosting companies share, the faster you can remove malicious sites.
Prevention requires attention and technical measures: use an ad blocker, extensions that alert on suspicious domains, multifactor authentication in all your accounts and regular financial statement verification. The coincidence between a major international event and a mass fraud campaign is predictable; the difference makes the user preparation. To check URLs and suspicious files you can use services such as VirusTotal, and for official alerts, always consult the primary sources, such as the FIFA page (https: / / www.fifa.com) and authorities' notices.
The emotion for the World Cup is legitimate, but online trust must be gained every time. If you are going to travel, buy tickets or hire packages, plan in advance, document your purchases and maintain protected payment channels: this reduces the likelihood of being a victim more in the fraud season around the tournament.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...