惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
博客园 - Franky
The GitHub Blog
The GitHub Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
小众软件
小众软件
罗磊的独立博客
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
美团技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
C
Check Point Blog
WordPress大学
WordPress大学
博客园 - 【当耐特】
博客园 - 司徒正美
D
Docker

Proofpoint News Feed

Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity | Proofpoint US Four groups caught using the same Chrome and Windows exploit kit CISOs are feeling the security burden of accelerated AI use Chinese espionage groups swarm to exploit triple-link chain of zero-days Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate | Proofpoint US Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models Proofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People Officer | Proofpoint US Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster | Proofpoint US Cybercriminals Turn to Indirect Prompt Injection Attacks Fox News Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats | Proofpoint US Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities | Proofpoint US Max-severity Exchange server flaw under active exploitation by Kremlin hackers New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | CNN Politics International alert spotlights Russia-linked attacks on Zimbra webmail US and allies say Russian hackers stole emails without social engineering If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective | Proofpoint US The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Suspected North Korean actors use fake ‘coding assignments’ to steal crypto China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US
FIFA World Cup 2026: More than One-Third of Official Part...
2026-04-14 · via Proofpoint News Feed

Analysis by cybersecurity company Proofpoint reveals that while most partners have implemented baseline email authentication, many are still not proactively blocking fraudulent emails that impersonate their brands

Proofpoint, a leader in cybersecurity and compliance, today unveiled the results of a study showing that more than one-third (36%) of the official sponsors, suppliers, partners and supporters associated with the FIFA World Cup 2026, which takes place from the 11 June to 19 July 2026, do not have the necessary email security measures in place to help protect themselves from domain impersonation. This may expose fans, customers, and partners to an increased risk of email fraud that impersonates trusted brands.

Cybercriminals routinely seek to capitalize on major global sporting events by targeting fans with social engineering scams posing as sponsors, airlines, hospitality brands, delivery services, or consumer brands, using lookalike domains and spoofed email. In the run-up to a tournament that drives a huge surge in travel, ticketing interest, promotions, and merchandise activity, the wider ecosystem must be strengthened against email-borne threats, the primary attack vector for fraud.

To establish the current state of defenses against impersonation risk, Proofpoint analyzed the level of adoption of DMARC (Domain-based Message Authentication, Reporting and Conformance) across a list of World Cup sponsor domains.

DMARC, the first line of defense against email fraud

In recent years, Proofpoint has observed cybercriminals using a range of tactics to impersonate legitimate organizations to reach their target, rather than hacking into and infiltrating their victims’ networks and technical infrastructure.

DMARC is an email authentication protocol designed to protect domain names from misuse by cybercriminals. It authenticates the identity of the sender before allowing a message to reach its destination. DMARC has three levels of protection: monitoring, quarantine, and reject; rejection being the safest way to prevent suspicious messages from reaching the inbox.

Implementing DMARC allows an organization to define what treatment should be applied to email messages using its domain name, as well as the policy to be applied in case of failure during verification: accept the email message (p=none, where p here stands for policy), categorize it as spam (p=quarantine), or delete it (p=reject).

Key research findings include:

The domain names that make up the FIFA World Cup 2026 sponsors, partners, suppliers and partners ecosystem were analyzed, with the following findings:

  • Out of the 25 domains analyzed, 24 (96%) have published a DMARC record at a basic level, indicating most organizations have begun implementing protections against email domain impersonation.
  • However, only 16 of the 25 domains (64%) actively protect their domain name with the strongest DMARC “reject” policy, the setting that prevents unauthenticated, spoofed emails from being delivered. 
  • This means more than one-third (36%) are not yet proactively blocking fraudulent emails that attempt to impersonate their brand.
  • Eight domains (32%) have DMARC set to monitoring mode or a partial enforcement posture, which provides visibility but does not stop spoofed emails from reaching inboxes.

Matt Cooke, EMEA Cybersecurity Strategist at Proofpoint, said: “Major events like the FIFA World Cup naturally generate huge excitement - from travel plans and ticket purchases to special offers and merchandise. Unfortunately, that also creates opportunities for scammers to take advantage of fans. While it’s encouraging that many partner brands have taken steps to improve their email security, too many are still leaving the door open to fraudulent messages. Without stronger protections in place, it becomes easier for criminals to impersonate trusted brands and trick people into sharing personal details or making payments for fake offers.”

Fans should be especially cautious in the run-up to the tournament and keep the following recommendations in mind:

  • The safest way to buy tickets is directly from FIFA, which does have a full DMARC 'reject' policy in place.
  • Be wary of unsolicited emails, texts, or calls - especially those urging urgent action or immediate payment.
  • Never share financial information or passwords via email or text message; if in doubt, contact the organization using official channels.
  • Use a unique password for each account and enable multi-factor authentication (MFA) where possible.

Learn more about DMARC visit: https://www.proofpoint.com/us/threat-reference/dmarc

###

Methodology:

To assess the level of DMARC adoption among the official sponsors of the FIFA World Cup 2026, Proofpoint conducted an analysis of the primary corporate domains of each organization listed on the FIFA website, along with Sports Business Journal. FIFA has a full DMARC “reject” policy in place. The analysis was carried out in February 2026.

About Proofpoint, Inc.

Proofpoint, Inc. is a global leader in human- and agent-centric cybersecurity, securing how people, data, and AI agents connect across email, cloud, and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 10,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint’s collaboration and data security platform helps organisations of all sizes protect and empower their people while embracing AI securely and confidently.  Learn more at www.proofpoint.com.


Connect with Proofpoint on LinkedIn

Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.