惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Vulnerabilities – Threatpost
D
Docker
C
Check Point Blog
P
Proofpoint News Feed
H
Help Net Security
A
About on SuperTechFans
GbyAI
GbyAI
MyScale Blog
MyScale Blog
F
Fortinet All Blogs
U
Unit 42
Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
I
InfoQ
Recent Announcements
Recent Announcements
Stack Overflow Blog
Stack Overflow Blog
博客园 - 三生石上(FineUI控件)
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
Simon Willison's Weblog
Simon Willison's Weblog
WordPress大学
WordPress大学
Attack and Defense Labs
Attack and Defense Labs
D
DataBreaches.Net
C
CXSECURITY Database RSS Feed - CXSecurity.com
人人都是产品经理
人人都是产品经理
J
Java Code Geeks
Help Net Security
Help Net Security
P
Proofpoint News Feed
Latest news
Latest news
L
LINUX DO - 最新话题
K
Kaspersky official blog
B
Blog
C
Cybersecurity and Infrastructure Security Agency CISA
S
SegmentFault 最新的问题
C
Cyber Attacks, Cyber Crime and Cyber Security
Project Zero
Project Zero
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
H
Heimdal Security Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
Jina AI
Jina AI
Vercel News
Vercel News
AWS News Blog
AWS News Blog
L
Lohrmann on Cybersecurity
aimingoo的专栏
aimingoo的专栏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
Hacker News - Newest:
Hacker News - Newest: "LLM"
W
WeLiveSecurity
Martin Fowler
Martin Fowler

Latest from TechRadar in Security

Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… How to meaningfully measure the effectiveness of cyber resilience 'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale… How EU organizations can turn sovereign cloud theory into action 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to… 'They mopped the floor with me and pulled every childish game they could': Disgruntled researcher releases second major Windows zero-day — claims Microsoft 'would ruin my life, and they did' 'As threats evolve, Gemini keeps our defenses one step ahead': Google claims its AI helped it block over 8.3… Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe Solving the shadow IT crisis in travel Agentic swarms will change how everyone uses AI – but how can organizations deploy them securely? Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains China completes testing on ‘deep-sea electro-hydrostatic actuator’ capable of slicing undersea cables as deep as 3.5 kilometers – new compact subsea vessel testing bridges the ‘last mile’ and could deploy in 2026 Many are still leaving the door open': Security experts warn FIFA World Cup partners could be putting customers at… 'Anyone with $10 could have walked straight through': Report warns this legit-looking software is actually… An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now 'This is not a traditional coding error': Experts flag potentially critical security issues at the heart of Anthropic's MCP, exposes 150 million downloads and thousands of servers to complete takeover Your OpenClaw agents can empty your inbox and leak your data. Here's how to secure them Russia hits European thermal power plant in attempted ‘destructive’ cyberattack – Pro-Kremlin hackers are engaging in ‘riskier and more reckless behavior’ in latest attempt to cripple Western critical infrastructure The war in Iran is reaching cyberspace - here’s how to prepare Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… Dozens of WordPress plugins hijacked to target thousands of sites 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy Closing the cloud complexity gap 'It's more common than you think': Experts reveal how hackers are trying to hijack your inbox with these… 'This wasn’t just phishing — it was a full-service cybercrime platform': FBI reveals takedown of notorious W3LL phishing operation targeting thousands of victims From cloud to Agentic AI: Why security must evolve faster than innovation Basic-Fit gym group data breach exposes details of over 1 million members — here's what we know ‘Authorities can ask them to hand over data’: Report claims over 80% of Europeans don’t trust US and Chinese businesses to handle their data – Europe is desperate for homegrown AI, cloud, and telecoms as the rift with the US grows Booking.com confirms reservation data breach — tells customers hackers 'may have been able to access certain… Agility is the key to protecting against Malware-as-a-Service (MaaS) Rockstar hackers publish 78.6 million stolen records — but many of us will be disappointed Adobe issues emergency security patch — Reader and Acrobat users need to update now What 2025 taught us about the importance of resilience in retail Governing the hidden risks of generative AI in the enterprise Russia launched a covert operation to deploy undersea sabotage vessels in UK waters while the world was distracted by the Middle East - UK threatens Putin with ‘serious consequences’ if subversion continues 'Industrial-scale scam operations': Global criminal organization operated slave compounds in Asia behind huge malware-as-a-service hydra targeting 35+ government agencies monthly OpenAI flags third-party data issue — all macOS users should update now Hackers use Claude and ChatGPT in 'a significant evolution in offensive capability' to breach government agencies, leak hundreds of millions of citizen records 'This is not your typical run-of-the-mill malware': CPUID download page hacked and tools replaced with links… How businesses can turn AI pilots into scalable solutions ‘No Decision’ is the new breach: Why inaction is becoming a career risk for CISOs in 2026 Rockstar confirms major third-party data breach: GTA VI maker says 'no impact on our organization or our… '$15K bill destroyed a solo developer’s startup': How hackers are using leaked Google API keys to… Adobe Reader users beware — experts flag months-old security flaw using booby-trapped PDFs to scope out victims Top WordPress Slider plugin hijacked to spread malware — here's what to look out for No, Elon Musk doesn't want to give you a $5,000 tax refund — it's a scam, here's what to look out… ‘It’s a potential national security threat’: Proton study finds over 3,500 US legislators’ official emails leaked and exposed on the dark web Microsoft warns worrying security flaw exposed over 50 million Android users, says 'user credentials and financial… Google Chrome rolls out a new tool to try and stop infostealer malware in its tracks Breach exposes sensitive LAPD files stored in city attorney system ‘FlamingChina’ hacker claims to have stolen over 10 petabytes of advanced military data from China’s National Supercomputing Center in possibly the biggest hack of all time Mac users beware — experts say this attack 'stood out immediately' by making a major change to try… Now that's different - hackers use miniature SVG images to try and hide credit card stealer Closing the implementation gap in America's cyber strategy UK NHS chief champions Palantir’s 'outstanding results’ in England, pushes for deeper rollout despite… French email provider accidentally leaked 40 million records — L’Oreal, Renault, French government data… Tame your AI gremlins before the chaos becomes permanent NHS Scotland domains reportedly found serving adult content and illegal sport streams 'This creates a layered form of obfuscation': New report says criminals are using emojis to avoid detection Top open source AI platform Flowise hit by maximum-level security issue US agencies warn Iranian hackers are targeting American critical infrastructure — causing 'disruptive effects… Third-party integration tool Anodot data breach hits Snowflake customers Always-on AI Agents put everything hackers could ever want behind a single attack surface When infrastructure decisions shape growth outcomes 'This puts organizations at risk of credential theft, data manipulation and broader compromise': UK government, Microsoft warn Russian hackers are hitting TP-Link home routers to hijack internet traffic 'A new frontier model trained by Anthropic that we believe could reshape cybersecurity': Project Glasswing wants to use AI to prevent AI cyberattacks — but will 'overeager' Claude Mythos do more damage than help? Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days to launch ransomware at targets… 'By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the… 'Stolen session cookies render MFA irrelevant': How $900-per-month turnkey malware is putting enterprise-grade… 'Verify before you act': security expert reveals the simple steps you can take to stay safe from deepfakes I can't think of anything that's off limits to them': FBI slams cybercriminals for attacking schools,… 'I was not bluffing Microsoft, and I'm doing it again': apparently disgruntled researcher leaks worrying… Understanding the ‘espionage ecosystem’ threat Goodnight REvil and GandCrab? Police think they've identified two of the biggest cybercrime bosses around Why modern cyber conflict is partly a global skills challenge 'Your login credentials may already be slipping into the hands of a cybercriminal': Hackers target LinkedIn… SparkCat malware returns to target Android and iOS users, hiding in innocent apps to try and steal your details One of the largest corporate espionage and data breach scandals in digital history': New "BrowserGate" report claims LinkedIn secretly scans user browsers for installed extensions and collects device data This devious VENOM phishing campaign targets business executives by name — so watch what you click on Backups won’t save you from this version of ransomware Your marketing stack is an attack surface – is security watching? AI agents can only be trusted as Junior Engineers Top museums hit by apparent cyberattack on Vivaticket — Louvre and other institutions affected Uffizi galleries confirms it was hit by cyberattack — but claims nothing was stolen Time for an upgrade? Report warns outdated operating systems could be the 'unnecessary risk' your business… Building private AI: control, compliance and competitive edge 'Skipping a beat on resilience investment isn’t an option any more': IT incidents can cost firms huge amounts - here's how to stay on top of issues 'The most powerful weapon is not always a missile': How Iranian "Charming Kitten" hackers used old… 'Growing 3x faster than police staffing': Surge in cybercrime and new laws on ransomware payment could put UK… The invisible threat hidden in clear view: how Unicode characters are being weaponized to hide malicious commands from… Be careful what you click - hackers use Claude Code leak to push malware Hims and Hers reveal cyberattack — customer support system hacked and personal info stolen, here's what we…
Ticket scams, fake streaming websites and dodgy domains: the security threats facing football fans ahead of the World…
Mike Moore · 2026-06-11 · via Latest from TechRadar in Security
A detailed view of the FIFA World Cup Trophy during the VIP Welcome Reception ahead of the FIFA World Cup 2026 Official Draw at John F. Kennedy Center for the Performing Arts on December 04, 2025
(Image credit: Michael Regan - FIFA/FIFA via Getty Images)

As the World Cup 2026 kicks off, the planet's biggest sporting tournament is set to draw in billions of viewers, as well as the hundreds of thousands of fans attending games across the USA, Mexico and Canada.

However the event is also set to be fertile ground for online scammers and hackers, who will be looking to capitalize on the excitement to trick unwary victims.

Here's our guide to spotting the most dangerous scams and tricks online during the World Cup - and how you can stay safe.

Fake streaming websites and apps

With the event taking place across the American continent and time zones, and entry to some of these countries already proving difficult, many fans will be forced to watch their country on broadcast television, or online.

Hackers are taking advantage of this by launching fraudulent streaming platforms, which may offer free or discounted access to matches, but are designed to steal login credentials, payment information, or personal data.

Unofficial streaming sites are also often filled with deceptive advertisements that can redirect users to phishing pages or trigger malware downloads, and cybercriminals may distribute unofficial apps that appear to offer match coverage but instead install malware or spyware on users' devices.

Arctic Wolf world cup stream warning

(Image credit: Arctic Wolf)

Arctic Wolf security researchers have warned that, with timing issues proving tricky for lots of fans, many will be searching for last-minute viewing options, and so some malicious sites recruit subscribers with a promise to drop a “free stream” link (pictured above) five minutes before each match begins, but then are designed to detonate at the last moment after luring victims in.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Even legitimate services may be at risk, as popular streaming services are frequent targets for credential-stuffing attacks, where stolen usernames and passwords from previous breaches are used to gain access to accounts.

So the name of the game - be on your guard when searching for online streams, and if an offer seems to good to be true - it probably is.

Online ticket scams

CYFIRMA world cup ticket scams

(Image credit: CYFIRMA)

With World Cup tickets in high demand by desperate fans, and FIFA attracting widespread criticism for the eye-watering prices introduced for this tournament, fans may understandably try turning to alternative sources.

However this may not be a great idea, as fans may encounter fake promotions, prize giveaways, or subscription offers tied to the tournament that are designed to collect personal information or payment details.

Arctic Wolf flagged one campaign using a ticket lure that includes a decoy JPEG to distract the victim, however when clicked on, an infostealer malware is dropped onto a victim's device, where it harvests browser secrets such as cookies, saved passwords, autofill and payment-profile data, browsing and search history, messaging and session material, clipboard contents and a desktop screenshot, saved Wi-Fi profiles and passwords, and a wide range of application credentials.

Fake domains

Along with more blatant scams, criminals are also busy preparing and running fake websites, again purporting to host ticket giveaways or offers, but in reality will just be stealing valuable personal data.

Arctic Wolf found that since January 2026, more than 10,000 new domains were registered under the broad umbrella of the World Cup, approximately 2000 new domains per month - many of which are legitimate, but the temptation is just too much for some scammers.

Experts from Cyfirma also reported such sites actually spiking in August and September 2025, as scammers tried to prepare early, with peak registrations exceeding 300 domains per day.

They warn that cloned FIFA interfaces may be combined with fake customer support channels or AI-generated phishing emails to increase legitimacy and improve victim conversion rates.

Unfortunately, the rise in AI-generated content will also further increase the likelihood of highly convincing multilingual scams targeting international audiences.

"Looking ahead, organizations supporting the FIFA World Cup 2026 should anticipate a dynamic threat environment where cybercrime, hacktivism, disinformation, and state-linked cyber activity increasingly overlap," the experts note.

"Continuous threat intelligence collection, proactive monitoring of malicious infrastructure, and coordinated cybersecurity efforts across public and private sector stakeholders will be essential to identifying emerging threats and maintaining operational resilience throughout the tournament lifecycle."

Real-world issues and hacks

Even at the games, you may still be at risk, as criminals may try and exploit the excitement of being at the tournament to target those letting down their guard.

In particular, fans should watch out for unverified public Wi-Fi networks, as areas such as airports, hotels, stadiums, and fan zones often become hotspots for rogue Wi-Fi networks designed to intercept credentials or redirect users to malicious websites.

The rise in QR-code usage has also led to an increase in QR-code scams, sometimes referred to as "quishing." These attacks can trick users into visiting fake sites offering tickets or giveaways that request personal information or payment details.

Arctic Wolf notes that quishing is even targeting the organizers of the tournament, with one scam targeting employees working on the games being held in the US city of Philadelphia.

The team found a purpose-built PDF entitled “Employee Handbook – Understanding employment at FIFA World Cup 26 Philadelphia”, styled with the Liberty Bell and a credible HR layout, and metadata names the city’s legitimate tourism organization (discoverphl.com) and an intended recipient inside.

However, the document ends by asking the victim to scan a QR code “to access the digital version of the handbook,” complete with a friendly step-by-step guide to opening their camera and tapping the (malicious) link.

So the message is - it doesn't matter who you are, or where you're watching, be on the lookout for potential scams, or the only own goal you could be facing is your own.

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.