惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
博客园 - Franky
The GitHub Blog
The GitHub Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
小众软件
小众软件
罗磊的独立博客
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
美团技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
C
Check Point Blog
WordPress大学
WordPress大学
博客园 - 【当耐特】
博客园 - 司徒正美
D
Docker

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
FIFA World Cup 2026: Hackers Target Football Fans With Fa...
Deeba Ahmed · 2026-06-19 · via Hackread – Cybersecurity News, Data Breaches, AI and More

With the FIFA World Cup 2026 matches in full swing, cybercriminals are targeting fans with various scams to capitalize on the tournament’s popularity, security researchers warn. Multiple scam networks have been discovered by security firms so far. These networks are designed to steal funds and personal details from people looking for tickets, hotels, and betting options.

Security researcher Prashant Kumar and his team at Forcepoint X-Labs recently tracked these threats. In a statement shared with Hackread.com, Kumar said, “I have looked for FIFA-themed phishing/malicious campaigns and observed a large, active, multi-variant phishing and fraud campaign abusing the FIFA World Cup 2026 brand.”

The team found three main scam types spread across more than 100 fake web links. The largest operation tricks fans into using illegal gambling platforms tied to ongoing matches through fake links like cn-web-fifacwc.com and zone-2026fifa.com.

These links, although they feature Chinese-language text, include custom versions tailored for international audiences in France, Africa, and Asia. Visitors are lured with promises of guaranteed rewards for placing bets on current games; however, in reality, they are redirected to credential-stealing pages.

Another active part of the scam uses 14 fake hotel booking networks customized for tournament cities like Dallas, Miami, and New York. Following the format “fifaworldcup2026cityhotels.com“, these pages were all registered within 32 minutes of each other to steal credit card details from travellers looking for last-minute rooms between fixtures. The hackers even cloned the real FIFA website structure under the web link fifa.monster to secretly track visitors and target them with follow-up spam advertisements.

Stealing bank codes

Other cybersecurity firms like CloudSEK and Netcraft found that these operations are highly organised. CloudSEK traced the main setup to threat actors in China who use an unauthorised payment control panel called tbpay.uk. To make the pages seem real, the hackers even embed a legitimate live chat service called tawk.to to talk to targets.

worldcup2026ticket.shop (Source: Netcraft)

As fans rush to secure seats for upcoming matches, these scammers are using realistic online checkout pages on links like ww-fifa.com. They do not just take card numbers for future use. Instead, they use a live setup to watch what the victim does on the page in real time.

Fake Ticket Shopping Cart (Source: CloudSEK)

When the bank sends a text message with a security code, called a one-time password or OTP, the scammers catch it as it is typed. This lets them evade the bank’s security check and hijack the victim’s account completely.

Forcepoint confirmed it is actively blocking these confirmed fake sites and their shared backend systems, while constantly writing new rules to stop the lookalike web links that scammers are creating every day during the tournament.