惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
Google DeepMind News
Google DeepMind News
P
Palo Alto Networks Blog
SecWiki News
SecWiki News
S
Secure Thoughts
P
Privacy International News Feed
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tenable Blog
W
WeLiveSecurity
Application and Cybersecurity Blog
Application and Cybersecurity Blog
A
Arctic Wolf
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Spread Privacy
Spread Privacy
V2EX - 技术
V2EX - 技术
Project Zero
Project Zero
C
CERT Recently Published Vulnerability Notes
Security Archives - TechRepublic
Security Archives - TechRepublic
Hacker News: Ask HN
Hacker News: Ask HN
Cyberwarzone
Cyberwarzone
Hacker News - Newest:
Hacker News - Newest: "LLM"
S
Schneier on Security
L
Lohrmann on Cybersecurity
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Scott Helme
Scott Helme
H
Hacker News: Front Page
博客园 - Franky
月光博客
月光博客
D
DataBreaches.Net
Know Your Adversary
Know Your Adversary
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
O
OpenAI News
N
Netflix TechBlog - Medium
G
GRAHAM CLULEY
Engineering at Meta
Engineering at Meta
博客园 - 叶小钗
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
B
Blog
人人都是产品经理
人人都是产品经理
I
Intezer
酷 壳 – CoolShell
酷 壳 – CoolShell
云风的 BLOG
云风的 BLOG
IT之家
IT之家
V
Vulnerabilities – Threatpost
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
LangChain Blog
Google Online Security Blog
Google Online Security Blog
博客园 - 聂微东
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网

Recorded Future

The Threat Isn’t the Frontier Model Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge Evaluating Mexico’s New Cybersecurity Plan The Purchase Scam Tactic Headed for the World Cup | Recorded Future FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems The Klue Security Incident and Its Impact on Recorded Future State Digital Surveillance Risk Landscape The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine Cyber-Enabled Maritime Sanctions Evasion Recorded Future Launches Impact and Metrics Dashboard China's Noncombatant Evacuation Operations: 2005–2025 Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars May 2026 CVE Landscape Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantage Threats to the 2026 FIFA World Cup Remembering Sir Alex Younger Iran Expands Handala Brand to Physical Threats The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It. At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026 April 2026 CVE Landscape Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defense NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals A Complete History of Cybersecurity: From Early Viruses to AI-Powered Threats The Different Types of Payment Fraud and How to Prevent Them Digital Citizenship Glossary: Key Terms Every Internet User Should Know Quantum Risk Explained Threat Activity Enablers: The Backbone of Today’s Threat Landscape Recorded Future Named a Leader in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. And there’s more. Hacking Embodied AI Working in London at the World’s Largest Intelligence Company Risk Scenarios for the US’s Strategic Pivot Building with AI: Here's What No Briefing Will Tell You Lazarus Doesn't Need AGI The Money Mule Solution: What Every Scam Has in Common From Overwhelmed to Autonomous: Rethinking Threat Intelligence in 2026 Critical minerals and cyber operations Today, trust is the superpower that makes innovation possible AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation? Evolution of Chinese-Language Guarantee Telegram Marketplaces Emerging Enterprise Security Risks of AI From Bazooka to Fake Nikes Your Supply Chain Breach Is Someone Else's Payday 4 Essential Integration Workflows for Operationalizing Threat Intelligence Recorded Future Iran War: Future Scenario and Business Implications A New Way to Buy Recorded Future: Solutions and Packages Built for the 2026 Threat Landscape March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day VIP Credential Monitoring Blog Third-Party Risk Is an Intelligence Operation. It's Time We Treated It Like One. Understanding and Anticipating Venezuelan Government Actions The Iran War: What You Need to Know Day in the Life: Product Manager at Recorded Future Panorama del cibercrimen en América Latina y el Caribe Latin America and the Caribbean Cybercrime Landscape Panorama do cibercrime na América Latina e Caribe Industrialization of the Fraud Ecosystem Blog The Shift: An Era of Quantum Geopolitics ClickFix Campaigns Targeting Windows and macOS 2025 Year in Review: Malicious, Infrastructure 2025 Identity Threat Landscape Report: Inside the Infostealer Economy: Credential Threats in 2025 February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January Latin America's Cybersecurity Turning Point: From Reactive Defense to Threat Intelligence Recorded Future Expands Coverage of Scams and Financial Fraud with Money Mule Intelligence from CYBERA January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day Preparing for Russia’s New Generation Warfare in Europe 2025 Cloud Threat Hunting and Defense Landscape GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack Network Intelligence: Your Questions, Global Answers Fragmentation Defined 2025's Threat Landscape. Here's What It Means for 2026 State of Security Report | Recorded Future From 27 Steps to 5: How Recorded Future Reimagined Threat Hunting with Autonomous Threat Operations Rublevka Team: Anatomy of a Russian Crypto Drainer Operation Autonomous Threat Operations in action: Real results from Recorded Future’s own SOC team | Recorded Future PurpleBravo’s Targeting of the IT Software Supply Chain Threat and Vulnerability Management in 2026 Best Ransomware Detection Tools December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity Practitioners Reveal What Makes Threat Intelligence Programs Mature GRU-Linked BlueDelta Evolves Credential Harvesting New ransomware tactics to watch out for in 2026 Digital Threat Detection Tools & Best Practices BlueDelta’s Persistent Campaign Against UKR.NET The $0 Transaction That Signaled a Nation-State Cyberattack China’s Zero-Day Pipeline: From Discovery to Deployment Cyber on the Geopolitical, Battlefield: Beyond the, “Big Fourˮ What’s Next for Enterprise Threat Intelligence in 2026 Palestine Action: Operations and Global Network Implications of Russia-India-China Trilateral Cooperation GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from October 5 Real-Word Third-Party Risk Examples When the Digital World Turns Physical: The Expanding Role of Threat Intelligence in Executive Protection Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat Actors The Bug That Won't Die: 10 Years of the Same Mistake The Hidden Cascade: Why Law Firm Breaches Destroy More than Data Intellexa’s Global Corporate Web The Maturity Gap: The Next Frontier in Threat Intelligence Inside the CopyCop Playbook: How to Fight Back in the Age of Synthetic Media AI Malware: Hype vs. Reality
2026 FIFA World Cup: What Public Safety Officials Need to Know
Megan Keeling · 2026-06-10 · via Recorded Future

Meanwhile, cities in the US and Canada are preparing for an elevated, though low-probability, threat of violent extremism. US or Canada-based supporters of the Islamic State have targeted sporting events in the past, notably the deadly attack on Bourbon Street in New Orleans, Louisiana, ahead of the 2025 Sugar Bowl. An attack on the upcoming World Cup would likely focus on soft targets such as fan zones, watch parties, and transportation and hospitality infrastructure, where security is less concentrated.

Geopolitical developments may also affect the threat environment. The Iran War elevates the risk of politically motivated activity by actors seeking to use the tournament’s visibility to draw attention to their cause. Recorded Future reporting has identified Iranian hacktivist personas shifting from promoting cyberattacks to physical attacks, such as arson. While this activity has previously centered around Israeli targets, accounts linked with these personas have expanded their online presence to other regions and languages following the start of the Iran War. As of this writing, Insikt Group has not identified evidence of activity connected to the World Cup.

Cybercriminals Already Exploiting World Cup Demand

Cybercriminal exploitation of World Cup demand and branding is already underway. Threat actors are using the tournament’s global visibility to impersonate FIFA, host cities, ticketing providers, retailers, and other organizations associated with the event. These operations create risks for fans, public-sector organizations, sponsors, affiliates, vendors, hospitality providers, transportation companies, and other businesses connected to the tournament.

In one purchase scam campaign active between April and May 2026, Recorded Future identified 33 World Cup-themed domains that lured users through a network of 2,500 online ads. These sites impersonated legitimate World Cup-themed stores to sell users products that did not exist, stealing their payments and credit card information along the way. In addition to fraudulent ads, these sites attracted visitors by compromising legitimate sites that appeared in search engine results and rerouting victims to scam sites.

The impact of these campaigns extends beyond individual victims. FIFA and other impersonated companies risk losing potential revenue from redirected customers and may also suffer reputational damage when customers associate a negative shopping experience with legitimate brands.

As the tournament approaches, suspicious domain registration activity is intensifying. In the weeks leading up to the tournament, over 1,000 suspicious domains had already been registered that used “World” and “Cup.” In a separate campaign, Chinese-speaking cybercriminals cloned FIFA’s official website across 300 domains, likely to harvest soccer fans’ credentials.

Insikt Group is also tracking hundreds of suspicious registrations of event-linked host city domains that cybercriminals could use to impersonate official World Cup sites, commit fraud, conduct phishing, or deploy malware. While much of the activity observed so far has impersonated FIFA brands, threat actors will likely expand operations to include vendors, hospitality and transportation providers, ticketing platforms, sponsors, and affiliates.

Threat actors are likely able to use AI to make impersonation attempts more realistic, increasing the risk that phishing, fraud, and social engineering operations will succeed. These activities introduce direct risks to World Cup sponsors and affiliates through brand abuse, financial fraud, credential theft, customer harm, and reputational damage.

High-Value Attendees and Organizations Face Targeted Cyber Risks

World Cup-related phishing and credential-harvesting activity will likely affect more than fans and consumers. State-sponsored actors may use World Cup-themed infrastructure for targeted espionage against senior government officials, diplomats, security personnel, journalists, executives, sponsors, vendors, teams, and other individuals of interest who are likely to attend or support the games.

Groups like Russia’s BlueDelta, for example, frequently use targeted lure material to harvest credentials from intelligence targets. World Cup-related lures could provide a timely and credible pretext for phishing emails, fake login portals, malicious attachments, or impersonation of legitimate event-related services.

Sponsors, affiliates, vendors, and supporting organizations also face ransomware and extortion risks. Threat actors may target companies associated with the tournament because disruption during a globally visible event increases pressure on victims to pay the demanded ransom. Hospitality providers, transportation companies, retail partners, software providers, ticketing platforms, media organizations, and other third parties may be particularly attractive targets because of their operational roles in the event ecosystem.

Even if core tournament infrastructure remains unaffected, ransomware or credential compromise affecting a sponsor, supplier, or local service provider could create operational disruption, reputational damage, and legal or compliance exposure.

Hacktivists and Influence Networks Look to Score Political Points

Online hacktivists will likely attempt to exploit international attention on the World Cup to amplify political causes. These groups may target host cities, tournament infrastructure, sponsors, affiliates, or supporting companies to maximize visibility and disruption. Many hacktivist operations involve nuisance-level activity, such as distributed denial-of-service attacks or website defacements, but some groups also seek sensitive information to expose in “hack-and-leak” operations.

In some cases, hacktivists have partnered with historically financially motivated groups to demand extortion payments for stolen data, using political pressure to strengthen extortion demands. This likely reflects the mutual benefit these actors see in exploiting high-profile and politically charged narratives to maximize pressure on victims.

Since the start of the Iran War, proxy hacktivists likely linked to Iranian intelligence services have actively conducted disruptive operations against private companies, including an attack on a medical device company that temporarily shut down operations. The connection to expertise and resources within Iranian intelligence makes these hacktivists more likely to carry out an effective attack.

While disruptive cyberattacks are less likely than cybercrime or espionage, even temporary disruptions could fuel negative political narratives. Any disruption, whether malicious or unintentional, is likely to be amplified by overt and covert information networks seeking to damage the reputation of host cities, sponsors, affiliates, or the tournament itself. So far, Insikt Group has observed overt channels, notably state-run television and traditional media outlets, as the most active in promoting narratives that undermine host-country legitimacy.

The combined threat of hacktivists and influence operators increases the risk that a cyber incident, physical disruption, or even a minor service interruption becomes part of a broader political narrative.

Keeping Ahead of the Threats

Public officials, sponsors, affiliates, vendors, and supporting organizations should prepare for the World Cup as a blended cyber-physical security challenge. Host cities should coordinate public safety, emergency management, transportation, venue security, and cyber defense planning. Corporate sponsors and affiliates should coordinate security, cyber, fraud, legal, communications, executive protection, travel, brand protection, and third-party risk teams before the tournament begins.

Monitoring for emerging threats can help organizations anticipate cyberattacks, criminal operations, or physical security concerns before they escalate. Key indicators include new malicious digital infrastructure, suspicious World Cup-themed domain registrations, phishing lures, credential-harvesting pages, increased reconnaissance activity such as network scanning, ransomware claims, dark web activity related to the World Cup, and hacktivist narratives targeting host countries, cities, sponsors, or affiliates.

Organizations should also track geopolitical developments, particularly those related to the Iran War, because political events could increase the likelihood of hacktivist activity, influence operations, or threats linked to political triggers.

The 2026 FIFA World Cup will bring together millions of fans, global brands, government officials, public safety agencies, and supporting businesses across three countries. However, its scale and visibility make it an attractive target for a wide variety of threat actors. Organizations that prepare across cyber, physical, fraud, brand, and communications functions will be better positioned to reduce risk, protect people, and limit disruption during the tournament.

See Threats to the 2026 FIFA World Cup for a full analysis of threats and mitigations.

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Their mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.