Don't score a security own goal this summer - our guide to spotting and swerving World Cup scams

A detailed view of the FIFA World Cup Trophy during the VIP Welcome Reception ahead of the FIFA World Cup 2026 Official Draw at John F. Kennedy Center for the Performing Arts on December 04, 2025
(Image credit: Michael Regan - FIFA/FIFA via Getty Images)

With the World Cup 2026 now well underway, the tournament is set to draw in billions of viewers globally, as well as bringing hundreds of thousands of fans to games across the USA, Mexico and Canada.

However the World Cup could also be fertile ground for online scammers and cybercriminals, who will be looking to capitalize on the excitement around the tournament to lure in unexpecting victims.

We’ve taken a look around, and found the most dangerous scams and tricks being found online during the World Cup - here’s how you can stay safe.

Ticket fraud and malicious domains

The scale of fraudulent web activity surrounding the 2026 FIFA World Cup is unprecedented, with researchers identifying over 10,000 newly registered World Cup-themed domains since the beginning of the year.

The use of generative AI has further lowered the barrier for entry, enabling the rapid creation of flawlessly designed sites that are increasingly difficult for users to distinguish from official channels.

Sophisticated threat actors have been spotted using pixel-perfect clones of official FIFA portals to deceive spectators, often mimicking legitimate checkout flows and payment options like Visa and PayPal to build victim confidence before carrying out card skimming and credential harvesting.

Beyond simple financial theft, these platforms are also being used to hijack legitimate FIFA accounts, allowing criminals to steal and resell authentic tickets held by fans.

Sophisticated mobile phishing and messaging scams

Mobile devices represent a major attack surface for the current tournament, primarily through "mishing" or mobile phishing campaigns.

These scams typically originate as deceptive "clean" posts on social media platforms — predominantly Facebook and Instagram — which funnel users into encrypted messaging applications such as WhatsApp, Telegram, or Discord, private environments where attackers are shielded from platform moderation, making it easier to deliver malware or social engineering lures.

These campaigns often exploit the intense emotional investment and "fear of missing out" associated with the tournament, offering highly discounted tickets or exclusive travel packages as traps.

Furthermore, researchers have identified "Man-in-the-Middle" frameworks capable of tracking a victim's live checkout journey and relaying one-time passwords (OTPs) in real-time to bypass multi-factor authentication.

Fake or malicious live-streaming platforms

The global demand for live match coverage has generated a fertile environment for fraudulent streaming services, with cybercriminals establishing fake platforms promising "free live coverage", but instead harvesting financial data or distributing malware.

A particularly aggressive tactic involves "last-minute" detonation, where malicious links are distributed via social media or messaging channels just minutes before a match begins.

This strategy relies on the urgency felt by fans who may neglect standard security diligence in their rush to view a game - and the FOMO feeling mentioned above.

Once accessed, these unofficial sites may prompt users to download "viewing apps" that are actually infostealers designed to exfiltrate browser data, login credentials, and personal files to attacker-controlled servers.

Public Wi-Fi threats

Spectators traveling to host cities also face significant risks - often from rogue public networks at high-traffic hubs, including airports, hotels, and fan zones.

Attackers frequently deploy malicious Wi-Fi hotspots designed to intercept sensitive credentials or redirect users to phishing domains.

This threat is exacerbated by the sheer volume of roaming traffic, which provides cover for signaling abuse and location tracking.

Vulnerabilities in older mobile signaling protocols can easily be exploited to intercept SMS-based communications or conduct billing fraud - and because traveling fans are often roaming in unfamiliar countries and are frequently distracted by the event, they are considered primary targets for opportunistic hackers looking to exploit device vulnerabilities in dense, high-pressure environments.

Bitdefender - Premium Security
Sponsored

Bitdefender - Premium Security

The ideal summer spot? Away from scams.
Travel safely and pack smart with Bitdefender.
Bank, stream, play, and download in full privacy.

MULTI DEVICE: Android | Windows | Mac | iOS

Your Premium Digital Protection: Complete Security and Enhanced Privacy·

- Best anti-malware protection, backed by the last 10 years of independent test scores
- E-mail protection for a scam-free digital life
- Scam Protection: AI-powered protection that detects and fights sophisticated scams
- Fully featured password manager to keep your credentials safe
- Unlimited & secure VPN traffic for complete online privacy