2026 FIFA World Cup threats laid bare

The 2026 FIFA World Cup is almost upon us, with footballโ€™s premier tournament kicking off on June 11. The bad news is that the cybercrime whistle has already blown, with everything from malicious FIFA-related domains and social media accounts to leaked and stolen credentials identified in a new threat intelligence report.

One cybersecurity expert has warned that this has created โ€œan incredible operational window for criminal networks,โ€ while another said that the threat goes beyond traditional network security challenges and has evolved into a โ€œmobile security stress testโ€.

The newly published FIFA World Cup 2026 Threat Report by Fortinetโ€™s FortiGuard Labs has analysed what it says has been โ€œa substantial increase in cybercriminal activityโ€ between January and May.

More than 13,000 FIFA-related domains were newly registered, which is to be expected considering the global nature of the event. Sadly, so is the fact that approaching 10% of these display malicious characteristics.

Now add the 1,700 social media accounts and channels that have popped up. Oh, and the prevalence of FIFA-related credentials within infostealer logs and breach datasets available on criminal forums.

It doesnโ€™t take a genius to understand the risk posed to account security from targeted attacks.

Main FIFA World Cup threats

While ticket scams are the most obvious of FIFA World Cup threats, the cybercrime window that has already opened lets attackers reach into a much broader grab-bag of threats.

โ€œThe true danger of many phishing schemes, like those leading up to and during the 2026 FIFA World Cup, lies in their ability to grant attackers access to credentials, enabling them to masquerade as trusted insiders,” warned Rex Booth, Chief Information Security Officer at SailPoint.

And the attackers know who to target; there is no groping around in the dark for victims here.

โ€œTheyย don’tย need to phish blindly when LinkedIn reveals your name, yourย employerย and your title,โ€ said Anne Cutler, Cybersecurity Evangelist at Keeper Security. โ€œThey know the accountsย you’reย creating right now for streaming and ticketingย almost certainlyย share a password with another more valuable account.โ€

This is why Cutler calls the World Cup one of the most dangerousย cyber-attackย windows on the planet, creating an incredible operational window for criminal networks. Those credentials get harvested,ย verifiedย and deployed weeks or months later, Cutler warned, long after the final whistle has blown.

And, importantly, long after anyone might connect the breach to a World Cup ticketing site. โ€œA fan who cuts corners in June becomes the entry point in September,โ€ Cutler concluded.

How to counter the FIFA World Cup threat

So what can FIFA and everyone else do?

The enterprise security defence playbook isย the same as it has always been. The security basics haven’t changed, nor have the controls. The Fortinet report makes this quite clear, recommending that security teams monitor for:

  • lookalike domains
  • brand impersonation
  • malicious advertisements
  • fake social media profiles
  • and credential leaks involving employees, partners and customers.

โ€œThey should also assess protections against phishing, malware, credential theft, and account takeovers,โ€ Fortinet advised.

The big problem for the FIFA World Cup is sheer scale.

Collin Hogue-Spears, Senior Director of Solution Management at Black Duck, warns that โ€œthe attack surface is three countries, 16 host cities, and every vendor that shares a domain with the tournament brand”.

With a third of FIFA’s own sponsors and suppliers having no Domain-based Message Authentication, Reporting, and Conformance record on their mail domains, Hogue-Spears said, cybercriminals donโ€™t even need to forge anything to spoof them.

โ€œTheย hard part is not knowing what to do,โ€ said Hogue-Spears, โ€œit is counting how many placesย have toย do it.โ€

Mobile security stress test

Which is where that โ€œmobile security stress testโ€ quote I mentioned at the start of this article comes back into the equation.

The World Cup leads to spikes in roaming traffic and dependence on mobile devices for tickets, payments, authenticationย and communications. This sheer volume of legitimate mobile activity โ€œcan make malicious behavior significantly harder to detect as attacks blend into normal traffic patterns,โ€ said Kern Smith, Vice President of Global Solutions at Zimperium.

โ€œAs cybercriminals adopt a mobile-first attack strategy and use AI to scale attacks faster than security teams can manually investigate, organisations supporting global events should think beyond infrastructure resilience and adopt an edge-to-core approach to defence.โ€

So, while network monitoringย remainsย critical, it has to be paired with real-time visibility into mobile devices and apps. Only this willย determineย whether activityย representsย a real incident. It will also help you understand business impact and accelerate the response before disruption spreads.ย 

As Smith put it, events like the FIFA World Cup mean that โ€œsecurity becomes a speed problem as much as a visibility problem”. And let’s not forget the Olympics is coming up this summer too.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.