FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
Security firms and the FBI say FIFA-themed scams are already targeting World Cup 2026 fans with fake sites, malware, and account theft.
Intelligence analysis by GPT-5.4 Mini

Researchers say fraud tied to the 2026 World Cup is already spreading through cloned FIFA sites, malicious streaming apps, fake ads, and stolen logins. The scams are built to cash in on ticket demand, free-stream hunting, and fan excitement before kickoff.
Scammers are setting up fake soccer ticket stores, fake login pages, and fake stream apps before the World Cup even starts. It is like someone opening a pretend candy shop outside a stadium and tricking fans into handing over money, passwords, and phone access.
Analysis
Scam ecosystem already in motion
The article says the World Cup is an obvious fraud target because tickets are scarce, demand is huge, and money is moving fast. Group-IB says it has tracked more than 4,300 fraudulent FIFA domains since August 2025, with one Chinese-speaking operation, dubbed GHOST STADIUM, running a phishing kit across more than 300 sites.
What the fake sites do
According to the report, the strongest scam copies FIFA’s login flow closely enough to resemble the real fifa.com sign-in page, including a genuine-looking single sign-on experience. The fake page also pushes password resets, which can let attackers take over accounts and resell tickets tied to them. Group-IB says the campaign uses Facebook ads, Telegram, WhatsApp, search results, and reused tracking codes to funnel victims in. It also notes payment paths that include card entry, money-transfer apps, local processors, and a crypto conversion option. FIFA’s official ticketing does not take crypto, making that a clear warning sign.
Malware and broader fraud
The piece broadens out beyond ticket theft. FortiGuard Labs reportedly saw more than 13,000 World Cup-themed domains from January to May, with about 8.8% flagged as malicious or suspicious. The FBI advisory lists fake FIFA domains and job pages, while other researchers found counterfeit merchandise shops, fake betting sites, and lottery emails promising large payouts.
The mobile threat is especially concerning. ThreatFabric and Kaspersky linked unofficial streaming apps to Android banking trojans, including Massiv and Perseus. These apps can abuse accessibility tools to overlay fake bank screens, capture typed data, intercept one-time codes, and remote-control the device. The article says the simplest red flag is a streaming app asking for accessibility access, since it has no legitimate reason to need it.
Key points
- Group-IB says more than 4,300 fraudulent FIFA domains have been registered since August 2025.
- A fake FIFA login operation is reportedly using more than 300 cloned sites to steal accounts and tickets.
- Malicious unofficial streaming apps can install banking trojans that steal passwords, codes, and payment access.
- Researchers also found counterfeit merch shops, fake betting sites, lottery emails, and spoofed FIFA social accounts.
- The FBI, FortiGuard, Kaspersky, ThreatFabric, Bitdefender, and Fortinet all describe parts of the same fraud wave.
The article says several defenders are already mapping the scam network, from Group-IB and FortiGuard to the FBI and Kaspersky. That visibility could help platforms, banks, and fans spot suspicious domains, ads, and apps sooner and reduce the number of successful attacks.
The scams are spread across many channels, so shutting down one site or account may not make much difference. The article also warns that phishing-as-a-service and reusable scam kits can keep the campaign going even after individual operators are removed.



