Cyber Fraud Surge Targets Soccer Fans Ahead of World Cup

by Sarah Steffens

In the final days before the world’s biggest soccer tournament kicks off, security authorities and digital crime experts have issued urgent warnings about an escalating wave of online scams designed to prey on passionate fans. These fraudulent operations are using fake websites, deceptive betting platforms, and data-stealing traps to exploit the global excitement surrounding the event.

The immense popularity of the tournament has turned it into a prime target for hackers and organized criminal groups, according to David Gonzalez Cuautle, a cybersecurity specialist at ESET. He explained that criminals often align their attacks with major events, and the World Cup offers an exceptional opportunity to cast a wide net for victims.

The threat is extensive. Fans face a digital minefield that includes phony tickets, non-existent VIP travel deals, counterfeit merchandise sold through bogus vendor sites, and malicious betting apps designed to pilfer financial information. There are also fraudulent streaming services that install spyware on devices, alongside fake websites meticulously crafted to resemble official tournament platforms.

The volume of these digital scams is staggering. By early last year, cybersecurity firms had identified roughly 4,300 fraudulent domains linked to the tournament. The situation became so severe that the Federal Bureau of Investigation issued a recent public alert, warning that cyber threat actors are actively targeting the official tournament website through spoofing attacks.

To lure unsuspecting users, scammers are registering domain names that combine tournament-related keywords with seemingly harmless extensions like .online, .shop, or .store. The schemes are also becoming more localized, with fraudulent websites appearing in multiple languages to target specific regions, Gonzalez Cuautle noted. While local law enforcement works to track these sites, the perpetrators often stay ahead by using disposable email addresses and pseudonyms to register them, making tracing difficult.

The financial impact of buying a fake ticket is just the beginning. For many victims, the real damage is the permanent theft of their digital identities. In a recent study, ESET analyzed a sample of these fraudulent websites and found that at least ten were not just quick scams but sophisticated data-harvesting operations, quietly stealing banking credentials and personal information.

Mobile users face similar risks. Fraudulent apps posing as sports broadcast or betting platforms often request excessive device permissions, enabling them to install malicious code or monitor user activity. Perhaps most troublingly, traditional signs of online safety no longer guarantee protection. Gonzalez Cuautle warned that the familiar padlock icon in web browsers, once a reliable indicator of encryption, can now be cloned by scammers.