The 2026 FIFA World Cup: Old Cyber Threats and New Challenges

Threat Discovery Telsy TS WAY Cyber Threat Intelligence

A Risk Scenario That Was No Longer New—But Featured a New Factor

The FIFA World Cup 2026 took place from 11 June to 19 July across the United States, Mexico and Canada, with matches hosted in 16 cities.

In the run-up to the tournament, several cyber and telecommunications threat assessment reports highlighted the event’s complexity, drawing comparisons—albeit on a much larger scale—with the security challenges faced during the Milan-Cortina Winter Olympics earlier that year.

Once again, the key concerns included the intense international attention surrounding the event, the interconnection of organizations operating across multiple critical sectors within a broad and diverse ecosystem, and the need to protect individuals (both high-profile figures and large crowds of spectators), infrastructure, data and brand reputation. In addition, significant socio-economic differences among the host countries resulted in varying levels of country-specific risk, both in terms of physical and cyber threats, requiring an exceptionally high degree of adaptability and coordination from all security stakeholders.

Analysts anticipated a wide range of malicious activities, including World Cup-themed phishing campaigns and credential harvesting targeting government entities, telecommunications providers, financial institutions, hospitality and merchandising businesses, as well as transportation and logistics operators. They also expected reconnaissance and network scanning against government and telecom infrastructures, endpoint compromises, and attempts to reroute data traffic through relay infrastructures. Particular concern was raised over the numerous technology, financial, business and infrastructure supply chains, which were identified as significant potential attack vectors.

The presence of NATO delegations, Ukrainian officials, prominent Iranian representatives, NGOs, civil rights activists, and media organizations representing diverse political perspectives increased the likelihood of state-sponsored cyber operations and hacktivist campaigns. At the same time, the tournament itself represented an ideal opportunity for influence operations and disinformation campaigns.

A largely unprecedented risk factor emerged from the gambling ecosystem. These were, in fact, the first FIFA World Cup matches to be played in countries where sports betting is both legal and socially significant. The mature U.S. market—characterized by widespread adoption, a mobile-first approach and comprehensive regulation—was complemented by Ontario’s regulatory framework and Mexico’s licensed betting operators, creating a mixed environment potentially vulnerable to criminal exploitation, particularly where regulatory gaps or inconsistencies existed.

Among the scenarios identified were brand abuse campaigns exploiting differences in gambling regulations between jurisdictions, where activities considered legal in one country might not be permitted in another. Beyond illegal or semi-legal operations conducted through social media channels, experts also anticipated significant fraud involving malicious domains and counterfeit betting applications.

 

Key Figures

Between January and May 2026, registrations of FIFA-themed internet domains reached tens of thousands. In early June, security researchers reported more than 1,700 social media accounts and channels falsely associated with FIFA and potentially exploitable for criminal activities. Approximately 4,600 URLs were also identified as distributing malware families including Nocturnal Stealer (Vidar), Lumma Stealer, and Redline Stealer.

During the same period, hundreds of credentials belonging to FIFA employees, along with hundreds of thousands of credentials belonging to users and fans visiting fraudulent FIFA-related websites, were reportedly exposed. The number of fake sports betting applications was estimated to have increased by 60 times in the weeks leading up to the tournament.

 

Streaming Under Attack: Fraud and Security Risks

Shortly before the knockout stage, the U.S. Government announced the seizure of hundreds of internet domains illegally streaming World Cup matches. The operation was coordinated by Homeland Security Investigations (HSI), part of the U.S. Department of Homeland Security, together with the International Computer Hacking and Intellectual Property (ICHIP) program, a network of U.S. federal prosecutors specializing in cybercrime and intellectual property enforcement.

The enforcement action extended beyond the United States, with domain seizures also taking place in Peru and Bulgaria, where two major online piracy hubs were targeted, as well as in Croatia, Romania, Poland and Colombia.

A potential security issue affecting this sector emerged while the tournament was underway. Ethical hacker BobDaHacker disclosed a vulnerability affecting a FIFA back-end API. After registering as an authorized football agent through the agents.fifa[.]org portal, the researcher was reportedly able to gain access to several internal FIFA platforms.

By bypassing client-side protections, she gained access to the live streaming management panel. From there, in addition to viewing every live match broadcast, she demonstrated that it would have been technically possible to manipulate the camera systems and alter the live video feeds.

In a blog post describing the findings, BobDaHacker reported that the platform also exposed access to information relating to matches, teams and equipment, the analytics dashboard, the real-time commentator information system, the FIFA AI Pro platform, and the development environment.

The vulnerability was responsibly disclosed to the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), which coordinated remediation efforts and ensured the issue was resolved.

 

TS-Intelligence

TS Intelligence_Telsy_Platform 2_LUG25

The information reported is the result of the collection and analysis work carried out by the specialists of Telsy’s Threat Intelligence & Response team with the support of the TS-Intelligence platform, a proprietary, flexible, and customizable solution that provides organizations with a detailed risk landscape.

It is available as a web-based and full-API platform, designed to be integrated into the organization’s systems and defensive infrastructures, with the goal of enhancing protection against complex cyber threats.

The platform’s continuous research and analysis on threat actors and emerging online threats—whether APTs or cybercrime—produces a constant stream of exclusive intelligence, delivered in real time and structured into technical, strategic, and executive reports.

Discover more about our Cyber Threat Intelligence services.