TrendAI™ identified 35,538 malicious sites exploiting the 2026 FIFA World Cup between January and June 2026, attracting roughly 1.48 million visits from Japan. The campaign comprises three scam types — fake merchandise shops, cloned ticket sites with real-time credit card and OTP harvesting, and fake live-streaming pages — all leveraging SEO poisoning to reach victims via search results. The cloned ticket sites are particularly dangerous, bypassing MFA by capturing one-time passwords entered by victims on the fake payment page in real time.
World Cup 2026
5 posts
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave World Cup-Themed Phishing Campaign Delivers Voidrift Malware with Highly Personalized Lures A sophisticated phishing campaign is leveraging highly personalized FIFA World Cup 2026 lures to deliver the evasive Voidrift malware. The attackers utilize extensive reconnaissance to embed target company logos into the email lures and host payloads on legitimate domains, successfully bypassing multiple prominent Secure Email Gateways.
Wardriving assessment across Mexico: Preparing for the 2026 World Cup A wardriving assessment across three Mexican host cities for the 2026 World Cup revealed significant wireless security risks, including high rates of vulnerable WPS configurations on otherwise secure WPA2/WPA3 networks. The prevalence of open networks, default SSID naming conventions, and BSSID exposure increases the attack surface for passive reconnaissance, rogue access point deployment, and adversary-in-the-middle attacks.
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface The 2026 FIFA World Cup presents a massive, multi-jurisdictional attack surface threatened by state-nexus disruptive operations and financially motivated cybercrime. Key risks include Iran-aligned actors targeting municipal OT infrastructure, pro-Russian hacktivists launching high-volume DDoS attacks against tournament services, and cybercriminals deploying ransomware against the hospitality supply chain.
18th May – Threat Intelligence Report This threat intelligence report highlights a surge in ransomware activity, critical zero-day vulnerabilities in Windows, and the active exploitation of Cisco Catalyst SD-WAN controllers. Additionally, it details emerging AI-driven threats, including malicious Hugging Face repositories and the abuse of AI website generators for phishing, alongside an APT intrusion by FamousSparrow targeting the energy sector.