Just in:
Venezuela defends sovereignty after Trump oil control claim // Chinese researchers engineer self-contracting muscle grafts // Russia brings cryptocurrency market law into force // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Qatar economy contracts 7% as energy output slumps // Dubai hotel provides free public co-working space // Apple raises evidence-destruction claims against OpenAI // Haldwani purification row: Caste back on political centre-stage // Putin holds talks with Pezeshkian in Bishkek // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // What Shein’s $27bn IPO means for Mubadala // Adobe widens Saudi AI access with $4 billion programme // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // US-Iran strikes revive confrontation across Hormuz and Jordan //

World Cup phishing network widens sharply

Cybercriminals are expanding phishing infrastructure built around the 2026 FIFA World Cup, with threat researchers mapping 222 malicious or suspicious domains to 203 unique IP addresses as fraud campaigns target fans, sponsors, travel operators and online shoppers before the tournament opens on 11 June.

The findings point to a much broader operation than the first wave of 79 lookalike domains that impersonated FIFA and ticketing-related services. The latest mapping suggests a distributed ecosystem rather than a single phishing cluster, with domains spread across multiple hosting providers and infrastructure groups to improve resilience, evade takedowns and redirect victims through different online paths.

The tournament, to be held across the United States, Canada and Mexico from 11 June to 19 July, is expected to draw exceptional online demand for tickets, accommodation, transport, merchandise, visas, streaming access and hospitality packages. That demand has created a lucrative window for fraud groups using fake FIFA branding, cloned storefronts, bogus ticket portals, counterfeit merchandise pages and deceptive travel offers.

Security analysts tracking the activity say the scale of the domain network shows attackers are preparing well before peak match-day traffic. Many domains use combinations of tournament terms, host city references, “official” branding, ticket language, team names and retail-style phrases designed to appear legitimate in search results or paid advertisements. Some pages are built to steal login credentials and card data, while others appear designed to collect deposits, harvest passport details or push victims into unauthorised betting and crypto schemes.

The 222-domain footprint also reflects a shift in tactics. Rather than relying on a handful of obvious fake pages, operators are spreading campaigns across many domains and IP addresses. That makes blocking harder for defenders because individual domains can be retired, redirected or replaced without dismantling the wider network. Several domains remain dormant before activation, a tactic known as domain ageing, which can allow fraudulent sites to appear less suspicious when they later begin hosting phishing pages.

Ticket demand remains the main pressure point. FIFA has repeatedly warned fans to use official channels, with the global interest in the expanded 48-team tournament likely to keep resale scams active. Fraudulent portals typically imitate the look of real ticketing pages, add countdown timers or “limited availability” messages, then direct users into payment flows that either steal funds outright or capture account and card details for later abuse.

Travel-related scams are also increasing. The three-country format has created complex itineraries for supporters crossing borders between host cities. Fraud pages are exploiting that complexity through fake visa assistance sites, accommodation listings, transport apps and package deals. Some sites falsely imply that a special World Cup visa is available, even though visitors must follow ordinary entry procedures for the relevant host country. These pages can be especially damaging because they may collect passport numbers, dates of birth, travel plans and payment details.

Merchandise fraud has become another major strand. Fake storefronts are using tournament logos, national team imagery and heavily discounted jerseys or souvenirs to lure buyers. Discounts of 80 per cent or more, unclear ownership details, poor refund language and pressure-driven sales prompts are common warning signs. Counterfeit retail pages are often supported by social media advertising, search placement and redirect chains that obscure the final destination until the buyer has already clicked.

The threat is not limited to fans. Official partners, sponsors, airlines, hospitality providers, broadcasters and national football bodies face a heightened risk of impersonation. Weak email authentication across parts of the event ecosystem can allow spoofed messages to reach consumers or commercial partners. Attackers may use fake sponsorship proposals, supplier invoices, accommodation offers or media accreditation messages to target businesses handling tournament-related payments.

Cybersecurity firms have also identified malicious sites using World Cup themes to promote unauthorised betting pools, fake prize draws and crypto tokens falsely implying links to the tournament. These campaigns rely less on technical sophistication than on timing, brand recognition and urgency. The use of AI-generated product images, polished copy and automated translation has made many scam sites harder for ordinary users to spot at a glance.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Alpha Dhabi lifts MICAD commitment to $1 billion // Russia brings cryptocurrency market law into force // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Venezuela defends sovereignty after Trump oil control claim // Jordan downs eight missiles as Iran targets US bases // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // US-Iran strikes revive confrontation across Hormuz and Jordan // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Apple raises evidence-destruction claims against OpenAI // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Qatar economy contracts 7% as energy output slumps // Putin holds talks with Pezeshkian in Bishkek // Adobe widens Saudi AI access with $4 billion programme // Chinese researchers engineer self-contracting muscle grafts //