40 fake FIFA World Cup 2026 ticket sites tied to fraud network: CloudSEK
Synopsis
Key Takeaways
At least 40 fraudulent FIFA World Cup 2026 ticketing websites linked to a coordinated cybercrime network involving 15 active operators have been uncovered, according to a report published on Friday, 12 June by cybersecurity firm CloudSEK. The operation, researchers say, goes well beyond conventional phishing and represents a sophisticated, scalable fraud platform targeting football fans worldwide.
How the Scam Works
The fake websites closely replicate legitimate FIFA ticketing portals, complete with official-looking branding, match schedules, stadium details, shopping carts, payment gateways, and reassuring 'secure checkout' messaging. According to CloudSEK, the campaign functions as a real-time man-in-the-middle phishing framework capable of tracking a victim's entire checkout journey.
The infrastructure can capture card numbers, expiry dates, and CVV information in real time, and reportedly possesses OTP interception capabilities to bypass SMS-based two-factor authentication — effectively neutralising a key layer of banking security.
The Infrastructure Behind the Operation
CloudSEK's investigation revealed a broader fraud ecosystem underpinning the campaign: a rogue payment processing network and a multi-tenant backend infrastructure supporting at least 15 separate operator instances. The backend is administered through a Chinese-language administrative panel, and researchers identified repeated access from China-based IP addresses, along with internal platform naming conventions consistent with Chinese-origin threat actors.
'This campaign shows how major global events are being weaponised by organised cybercriminal groups. The threat is no longer limited to fake ticket listings or basic phishing pages. We are now seeing full checkout impersonation, live victim tracking, card skimming and OTP interception capabilities being combined into one operational platform,' said Gagan Aggarwal, Threat Intelligence Researcher at CloudSEK TRIAD.
Social Media as a Traffic Engine
The report highlights the outsized role social media platforms are playing in funnelling victims to the scam sites. Facebook accounts for roughly 60–65 per cent of observed user sessions directed to fraudulent portals, while Instagram contributes approximately 15 per cent. This suggests the operators are running paid or organic promotion campaigns on mainstream platforms to lend their sites an air of credibility.
Who Is Being Targeted
The victim footprint spans multiple countries. Primary targeting has been observed in the United States, with additional activity detected across Italy, Romania, Australia, Canada, Germany, South Korea, Saudi Arabia, South Africa, and several other markets. This is notably the second major wave of FIFA-themed cyber fraud reported ahead of the 2026 World Cup, which is scheduled to be hosted across the United States, Canada, and Mexico.
What Fans Should Do
Cybersecurity experts advise fans to purchase tickets exclusively through FIFA's official website and to verify URLs carefully before entering any payment information. Enabling virtual card numbers for online transactions and being sceptical of social media advertisements offering discounted or last-minute tickets can significantly reduce exposure. Authorities in multiple countries are reportedly being alerted to the findings.