The images in this article were generated with artificial intelligence. How we publish
The opening of the FIFA 2026 World Cup not only activated stadiums and transmissions, it also launched a fraud infrastructure that, according to the research of Check Point, was built and positioned in advance. What is surprising is not so much the intensity of the attack, but its planning and the deliberate selection of technical and reliable vectors: supplanted emails, cloned apps in official stores and lookalike domains intended to steal payments or credentials. This combination makes any actor in the supply chain - airlines, hotels, catering providers, betting platforms - a potential back door for fraud.
A critical finding that requires immediate attention is that more than a third of the official partners analyzed lacked DMARC with policy of rejection, allowing mail to pass through legitimate domains without technical barriers. When communication of suppliers and payments transits at high speed and with little time for verifications, the lack of mail authentication is an open invitation to fraud. For any organization that handles billing or repayments in this context, this makes it clear that email protection should be an operational priority, not just a good IT practice.

No less worrying was the detection of dozens of apps that imitated bookmarks, published on Google Play at a peak a few months before the tournament. The observed coordination - multiple developer accounts publishing apps that supplant different brands - indicates an organized effort to capture deposits and generate commissions through affiliate and tipsters channels in Telegram. The threat here is not just malware; they are sophisticated social engineering frauds that exploit user confidence in official stores and in "expert" recommendations on closed channels.
The massive construction of false domains oriented to travel and hospitality completes the panorama. A substantial number of these websites were recorded in a few registrators and preferably under low-cost and low-governance TLDs, such as .top, which offer the attackers stable and abusing infrastructure. In addition, the presence of MX records in some of these domains reveals a clear intention: to receive emails, intercept password restoration flows and complete supplanting operations with apparent responses from the victim domain. A false domain with MX configured leaves the way open for complete interception attacks, from phishing to accountability.
The practical consequences for safety and risk equipment are direct: the most dangerous window did not start with the initial whistle of the tournament, but months before, during the pre-positioning phase. This requires that protection be seen as a continuous process of external exposure: to detect fraudulent domains and apps, to monitor high-abuse registrators and TLDs, and to respond with rapid and effective remediation models. In this type of campaign, the difference between suffering massive losses and containing the damage is in the speed of detection and the ability to remove the malicious infrastructure.
In practical terms, some immediate and effective measures that should be implemented include the strict application of DMARC with p = reject with correctly configured SPF and DKIM; the constant monitoring of new domain records and changes in MX records; the monitoring of TLS certificate emissions for cloned domains; and the adoption of mandatory verification processes for any payment instruction coming by mail or messaging. Mail authentication and visibility over DNS name space are controls that drastically reduce the abuse window. For technical details on DMARC and why its adoption is essential, see specialized resources such as DMARC.org.

On the front of mobile applications, protection requires a combination of prevention and detection: to strengthen official publication (signatures and identity verification of the developer), to monitor app stores for imitators, and to prepare quick reporting channels with platforms (e.g., reporting mechanisms on Google Play). At the same time, affiliate programmes need more stringent KYC and behavioural controls to prevent operator tipsters from capturing commissions on fraudulent deposits. For research and services that track these campaigns, see the work of specialized groups such as Check Point Research and intelligence resources on threats from mail and security companies.
Finally, the organizational response matters as much as the technical measures. Security teams should be coordinated with finance, shopping and communication: establish out-of-band verification routes for significant payments, use virtual cards or payment accounts specific to critical suppliers, and prepare public and legal messages to accelerate takedowns. Operational preparation reduces reputational and economic impact; lack of coordination between security and business amplifies damage.
The pattern observed around the World Cup is an extended lesson: great events concentrate not only fans, but incentives for fraud. The defence requires anticipation, external visibility and rapid action capacity. If your organization is in an exposed sector - finance, travel, hospitality or gambling - this season should be treated as a period of high and sustained risk; the evidence itself suggests that the attackers have already taken positions. To deepen findings and detection methodologies, review public reports and consider contact lines with brand-name exposure and protection services offered by specialized suppliers.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...