Cybersecurity researchers have uncovered a massive cybersecurity threat involving a **World Cup fraud campaign** targeting football fans ahead of the 2026 tournament.
Group-IB identified more than 4,300 fraudulent domains impersonating the official web presence of the International Federation of Association Football (FIFA). Meanwhile, the tournament is scheduled to begin on June 11, 2026, across the United States, Canada, and Mexico.
According to the research, a financially motivated threat actor known as GHOST STADIUM is operating at the center of this activity. The group runs a phishing network across more than 300 active domains. In addition, approximately 3,800 additional domains registered since August 2025 remain parked and ready for activation as the tournament approaches.
The Scale of the World Cup Fraud Campaign
The threat actor created a clone of the official FIFA website and its PingIdentity single sign-on login flow. This kit automatically translates into 11 languages and hijacks official brand assets directly from FIFA’s content delivery network. Furthermore, the fraudsters use Facebook ads to drive traffic, offering premium seats for as low as $60 to lure victims.
Group-IB estimates that fraud from premium and hospitality ticket tiers alone could cause losses between $71 million and $474 million. Consequently, total losses across all tiers of the **World Cup fraud campaign** could reach billions of dollars. Notably, more than 2,500 valid FIFA account credential pairs are already circulating on dark-web markets due to infostealer malware.
Parallel Fraud Schemes and Malware
The investigation revealed multiple parallel schemes targeting different aspects of the fan experience. Specifically, attackers are deploying counterfeit merchandise storefronts in Latin American markets. Globally, fans seeking alternative viewing options are targeted by fake streaming platforms that require subscription fees and infect devices with Remote Access Trojans.
These consumer-facing scams rely on a strong infostealer malware pipeline. By utilizing malware families such as Vidar and Lumma, threat actors continuously harvest browser-stored data on a global scale. This integration of phishing, malware, and fake marketplaces demonstrates how digital crime has evolved into an industrialized network.
The Cyber Fraud Fusion Response
To combat these threats, Group-IB highlights the need for a coordinated defense architecture. The company proposes the Cyber Fraud Fusion framework to connect detection, intelligence, and investigation into a unified system. This approach aims to predict and disrupt fraud before financial losses occur, moving away from reactive website takedowns.
Security Recommendations for Fans
Fans are urged to purchase tickets exclusively through the official FIFA ticketing portal at fifa.com. Any ticket offer requiring cryptocurrency payment should be treated as fraud, as the official portal does not accept digital currencies. Users should also enable multi-factor authentication on their accounts immediately.





