Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave
TrendAI™ identified 35,538 malicious sites exploiting the 2026 FIFA World Cup between January and June 2026, attracting roughly 1.48 million visits from Japan. The campaign comprises three scam types — fake merchandise shops, cloned ticket sites with real-time credit card and OTP harvesting, and fake live-streaming pages — all leveraging SEO poisoning to reach victims via search results. The cloned ticket sites are particularly dangerous, bypassing MFA by capturing one-time passwords entered by victims on the fake payment page in real time.
- domainuniversus[.]streamFake live-streaming site posing as a sports streaming service, hosting pages named after real World Cup matches with a fake video player and embedded malicious ad network
Detection / Hunteropenrouter
What Happened
Cybercriminals created over 35,000 fake websites pretending to be official 2026 FIFA World Cup ticket sellers, merchandise shops, and live-streaming services. These fake sites were visited about 1.48 million times by people in Japan alone. The most dangerous scam involves near-perfect copies of the official ticket site that steal credit card numbers and one-time passwords in real time, allowing attackers to make fraudulent purchases even when the victim's bank sends a verification code. The fake streaming sites never actually show any video — instead, they redirect users to other websites through a malicious advertising network to generate fraudulent ad revenue. People should go directly to official websites instead of clicking search results or ads, be suspicious of words like 'free' or 'official,' and never enter a one-time password on a site reached through a search result.
Key Takeaways
- Over 35,000 malicious sites tied to the 2026 FIFA World Cup were identified between January and June 2026, drawing approximately 1.48 million visits from Japan alone.
- Three primary scam types were observed: fake merchandise shops, near-perfect clones of official ticket sites, and fake live-streaming pages that never show actual match footage.
- Cloned ticket sites perform real-time phishing of credit card details and one-time passwords, bypassing MFA by tricking victims into entering OTPs on the fake site itself.
- Fake live-streaming sites abuse compromised legitimate websites (including a US university research institute) via SEO poisoning to rank highly in Japanese search results.
- Fake streaming sites embed a malicious ad network, redirecting users to legitimate financial trading and e-commerce sites as part of an ad fraud scheme.
Affected Systems
- Web browsers and mobile devices of users searching for World Cup tickets, merchandise, or live streams
- Japanese-language internet users particularly targeted
- Compromised legitimate websites (including a US university research institute domain) used for SEO poisoning
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victims reach scam sites via SEO-poisoned search results for World Cup tickets, merchandise, or free live streams
- Reconnaissance: Attacker infrastructure includes compromised legitimate websites (e.g., US university research institute) hosting embedded fake pages to boost search rankings
- Credential Harvesting: Cloned ticket sites collect email/password login credentials and credit card details from victims who believe they are on the official FIFA site
- MFA Bypass: Attacker uses stolen card details in real time; victim receives OTP from their bank and enters it on the fake site, which the attacker immediately uses to complete a fraudulent payment
- Monetization: Fake streaming sites redirect users through relay pages on blogging platforms to malicious ad networks, generating ad fraud revenue or enrolling victims in unwanted subscriptions
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules, queries, or signatures are provided in the article. The article references TrendAI™ and Trend Micro ScamCheck for web threat protection but does not include specific detection logic.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | This is primarily a web-based phishing and social engineering campaign. EDR telemetry on endpoints would only capture browser navigation events, which are typically low-fidelity for detecting phishing site visits. |
| Network Visibility | Medium | Web proxy, DNS logs, and URL filtering logs could reveal connections to the identified malicious domains and URLs. However, the use of compromised legitimate infrastructure (university domains) for relay pages makes network-level detection more challenging. |
| Detection Difficulty | Hard | The campaign abuses legitimate infrastructure (university websites, blogging platforms) for relay pages and uses SEO poisoning to appear in top search results. Cloned sites load resources directly from official FIFA servers, making them appear more legitimate. The scale (35,000+ sites) and rapid infrastructure rotation make blocklist-based approaches insufficient. |
Required Log Sources
- Web proxy logs (URL and domain access)
- DNS resolution logs
- URL filtering / web gateway logs
- Email security gateway logs (for phishing emails linking to scam sites)
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for users accessing domains that mimic official FIFA or World Cup branding but are not on a known allowlist of legitimate FIFA-affiliated domains, especially those accessed via search engine referrers. | Web proxy logs, DNS logs, URL filtering logs with referrer header data | Initial Access | Medium — legitimate users may access unofficial but benign World Cup fan sites or news aggregators. |
| Consider hunting for traffic to streaming-related domains that have embedded redirect chains through blogging platforms or compromised educational institution domains, particularly those with Japanese-language URL parameters. | Web proxy logs with full URL paths, DNS logs, HTTP referrer chains | Execution | Medium — some legitimate streaming aggregators use similar redirect patterns. |
| Consider hunting for users who enter credentials or payment information on sites that load static assets (images, videos) from official FIFA domains but are hosted on unrelated domains, indicating possible site cloning. | Web proxy logs with full URL paths and referer data, CASB logs | Credential Harvesting | Low — legitimate FIFA partners would be on known allowlists. |
Control Gaps
- Traditional URL blocklists may not keep pace with the volume and rotation of 35,000+ scam domains
- SEO poisoning results may bypass secure web gateways that do not inspect search result destinations in real time
- Compromised legitimate domains used as relay pages may be on existing allowlists, bypassing URL filtering
- Real-time OTP phishing cannot be detected by traditional credential stuffing or account takeover detection since the victim voluntarily enters the OTP
Key Behavioral Indicators
- Domains containing 'fifa' or 'worldcup' keywords that are not on official FIFA domain allowlists
- Web pages loading static assets from official FIFA servers while hosted on unrelated domains
- Redirect chains from compromised educational institution domains through blogging platforms to streaming-themed sites
- Sites with Japanese-language URL parameters or page titles mimicking Japanese broadcasters for World Cup content
- Pages with fake video player interfaces that trigger ad network redirects on play button click
False Positive Assessment
Medium — Many legitimate fan sites, news aggregators, and unofficial World Cup discussion sites may contain 'fifa' or 'worldcup' keywords. Blocking solely on keyword presence would generate significant false positives. However, the specific domains and URLs identified (e.g., universus.stream) are low false positive risk.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider adding the identified domain 'universus.stream' and associated URLs to your web filtering blocklists if applicable to your environment.
- Consider alerting users within your organization about World Cup-themed phishing sites, particularly those targeting ticket purchases and free live streams.
- If your organization has users in Japan or Japanese-language users, consider prioritizing awareness communications given the reported targeting of Japanese users.
Infrastructure Hardening
- Evaluate whether your web filtering solution can perform real-time content analysis to detect cloned sites that load assets from official domains while hosted elsewhere.
- Consider implementing DNS-based blocking for known scam domains identified in this campaign, if supported by your DNS infrastructure.
- If your organization operates public-facing websites, consider monitoring for unauthorized modifications that could be used for SEO poisoning or fake page embedding, as seen with the compromised university research institute.
User Protection
- Consider deploying browser security extensions or endpoint web protection that can flag or block access to known scam and phishing sites.
- Encourage users to navigate directly to official websites by typing the URL rather than clicking through search results or ads for event tickets or streaming.
- If applicable, consider enabling transaction verification alerts through your organization's financial services for employees with corporate cards.
Security Awareness
- Consider incorporating World Cup-themed scam awareness into existing security awareness programs, emphasizing that 'free' and 'official' in search results are red flags.
- Educate users that one-time passwords should only be entered on the card issuer's verified page, not on a merchant site reached via search results.
- Remind users to verify the merchant name and amount in any OTP SMS against their actual intended purchase before entering the code.
- Consider advising users to use unique passwords per service to prevent credential reuse attacks if credentials are harvested from a cloned site.