惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
量子位
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
L
LangChain Blog
A
About on SuperTechFans
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
美团技术团队
博客园 - 三生石上(FineUI控件)
N
Netflix TechBlog - Medium
D
DataBreaches.Net
P
Proofpoint News Feed
小众软件
小众软件
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
WordPress大学
WordPress大学
雷峰网
雷峰网
G
Google Developers Blog

The Record from Recorded Future News

Taiwan charges two businessmen over alleged role in Chinese espionage campaign Former UK privacy chief preparing legal action against woman who reported him, minister says Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip EU unveils cyber plan to reduce reliance on foreign AI systems Supreme Court allows Texas app law requiring age verification to take effect Britain plans to build autonomous AI 'Cyber Shield' to defend nation Major Japanese telco says cyberattack exposed 12 million emails UK cyber pledge draws only a handful of top firms despite ministerial appeal Canadian spy agency reports hacking three criminal groups in 2025 Attackers vote themselves $20 million in BONK cryptocurrency Major medical device manufacturer notifies nearly 4 million of breach Japanese teen arrested over cyberattack that disrupted anime streaming service Ukrainian media outlets now among 'priority targets' for Russian hackers Spyware found on phone of European Parliament member probing it Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis Supreme Court decision threatens EU-US data transfer agreement Teen suspect in Scattered Spider hacks is extradited to US US lifts export controls on Anthropic’s frontier cybersecurity AI models Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches CIA chief highlights major shifts in agency’s tech approach House passes kids’ online safety bill, but Senate approval unlikely An intelligence budget 'super user' job is now in the hands of Russ Vought Justices rule that cellphone location histories are protected by the Fourth Amendment US racks up about 400 wins over illegal World Cup streaming sites US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp Ukraine to use seized crypto from cybercrime group to buy war bonds Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Turla group adds more malware to Russia’s espionage efforts against Ukraine Russia used social engineering to breach prominent messaging accounts, Ukraine says FCC votes to toughen rules in bid to better protect undersea cables
Chinese-speaking fraud gang could be stealing millions fr...
Alexander Martin · 2026-05-28 · via The Record from Recorded Future News

Chinese-speaking fraudsters have built a near pixel-perfect clone of FIFA's official website across more than 300 domains in an attempt to steal credentials and payment details from fans seeking tickets to the 2026 World Cup.

The operation — one of four independent campaigns detailed Wednesday by cybersecurity firm Group-IB — could put billions of dollars at risk when accounting for credential theft, fake ticket sales, counterfeit merchandise, fraudulent streaming sites and unlicensed gambling platforms, said the Singapore-based company.

The potential scale of the fraud mirrors the scale of the 2026 World Cup, which is set to be the largest edition of the tournament in history, with 48 teams competing across 104 matches in the United States, Canada and Mexico.

The group behind it, which Group-IB designated GHOST STADIUM and first observed in November 2025, is one of four independent threat actors the firm identified targeting the tournament. Collectively those criminals have registered more than 4,300 fraudulent domains impersonating FIFA's official web presence since August 2025.

More than 300 of those domains are actively running fraudulent infrastructure. Approximately 3,800 more are parked or dormant, pre-positioned for activation as the tournament approaches, said the researchers.

“This is not a crude phishing page — it is a meticulously engineered impersonation,” the company warned.

GHOST STADIUM uses a phishing kit developed with Layui 2.7.6m, a Chinese open-source UI library that Group-IB said was “virtually unknown outside the Chinese developer community.”

The phishing kit clones FIFA's login system by replicating the authentication flow used by FIFA's identity provider by silently redirecting the user back to the real FIFA website, making the interaction appear to be a successful login.

The phishing page also requests a password reset parameter, enabling the attacker to immediately lock the victim out of their own account. Any legitimate tickets associated with the compromised account can then be resold, said the researchers.

Chinese-language comments were found embedded throughout the source code, said Group-IB. Infrastructure analysis found shared SSL certificates and Meta Pixel tracking IDs embedded identically across all 300-plus domains, tying the entire network to the same Facebook advertising accounts.

Among the 300-plus phishing domains identified by the researchers, 79 were exclusively selling premium and hospitality-tier tickets, priced between $1,500 and $10,000 or more. Group-IB said that with more than 600 victim registrations observed at a single domain, they estimated potential victim count exceeding 47,400 people for premium ticket fraud alone — with losses estimated at between $71 million and $474 million.

Those figures only cover approximately a quarter of the active GHOST STADIUM campaign. Group-IB said total losses across all fraud tiers, including credential theft, lower-tier ticket sales and downstream monetization, “could reasonably reach into the billions.”

According to the company’s investigators, the GHOST STADIUM campaign was primarily being distributed through paid advertising on Facebook offering tickets as cheaply as $60 for seats officially priced in the thousands, with “first come, first served” messaging designed to pressure purchases.

Group-IB advised fans to buy tickets only through fifa.com, typed directly into a browser, and to treat any domain using a hyphenated variant of the FIFA name as fraudulent. The firm said it notified relevant authorities and that its investigation ran from March to May 2026.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79