Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

I’ve got it World Cup ticket. It’s arrived in your inbox with a QR code, professional branding, and a confirmation email that looks like it’s real. Unfortunately, it wasn’t.
For years, discovering a to cheat It was relatively simple. A suspicious email address, incorrect English, or an obvious typo is often enough to raise suspicions. But in 2026 FIFA World CupThose old warning signs disappear. websites generated by artificial intelligence, Deep fake videosFabricated audio and disguised phishing campaigns make it easier than ever for criminals to impersonate legitimate organizations.
With the United States, Canada and Mexico hosting 104 matches in 16 cities, the largest World Cup in history has created an unprecedented opportunity for cybercriminals.
More than 13,000 FIFA domains were registered between January and May 2026. By early May, roughly one in 41 domains had been identified as suspicious or malicious — before a single match had been played, according to Tarek Jammoul, regional managing director at cybersecurity firm TrendAI.
FIFA estimates indicate that more than 6 million fans Stadiums will be filled to watch the tournament. In fact, more than 150 million tickets were ordered during the first 15 days of the sales window alone, making this edition almost It was subscribed 30 times Compared to previous tournaments.
“The World Cup is a perfect opportunity for fraudsters, and you can’t create a better one,” says David Holtzman, chief strategy officer at Naoris Protocol, a cybersecurity and blockchain technology company. “That’s football. It’s fun and harmless, which lowers people’s defenses.”
For more than a decade, phishing has emerged as a… The most common type From online scams. Phishing – a more targeted form of phishing in which attackers use information gathered from search engines, social media and other online sources to create more persuasive messages – poses a greater threat to World Cup fans this year.
The scale of the operation is enormous. The research conducted by cybersecurity company Group-IB was identified More than 4300 Fraudulent domains impersonating FIFA’s official online presence, along with six parallel fraud schemes and four independent threat actors operating prior to the tournament.
Common scams include fake ticket sales, Fraudulent immigration or misleading visa-related services and accommodation offers. Fans are also warned to be on the lookout for counterfeit merchandise and websites impersonating the tournament’s official branding.
“When we supported Qatar’s Supreme Committee for Delivery & Legacy (SCDL2022) (at the 2022 FIFA World Cup), the threats we helped identify were serious but still relatively identifiable — fake ticket pages, survey scams offering free mobile data, and a malicious Android app promising live streaming, among others,” says TrendAI’s Jamul.
The scams themselves have not changed significantly. The difference is the technology behind them.
“in Qatar 2022We’ve seen fake streaming domains, doxxing scams, and crypto schemes using images of football players. “Those same classes are being offered again now, just bigger and more AI-intelligent,” says Jamul.
“There has been an astronomical increase in fraud over the past couple of years, and AI is the main reason behind that,” says Holtzman, of Nauris Protocol. According to experts, AI does not invent completely new attack methods, but rather makes attackers much more efficient than they were before.
By creating highly professional emails at scale and helping attackers create convincing fake websites, AI is dramatically expanding the threat landscape.
At the same time, AI has also become one of the most powerful defensive tools in the cybersecurity industry. By analyzing massive amounts of data and detecting unusual patterns, it can help identify suspicious areas and anticipate emerging threats. But technology alone may not be enough.
Businesses increasingly rely on collaboration between platforms, cybersecurity companies, and law enforcement to track potential threats. For example, Mita says she has worked through initiatives such as Global Signal Exchange (GSE) and Fraud Information Exchange (FIRE) to identify and disrupt coordinated fraud targeting users.