























Lead Analysts: Jeewan Singh Jalal and Louis Tiley
KnowBe4 ThreatLabs tracked phishing campaign activity from the first week of April through June 22, 2026 — covering the pre-tournament build-up, tournament kickoff and the first twelve days of live match play. Our latest intelligence adds crucial mid-tournament telemetry (June 15-22), a newly identified reply-back campaign track and additional infrastructure intelligence.
Every major global event generates a parallel wave of opportunistic fraud. The FIFA World Cup 2026 is no exception. KnowBe4 ThreatLabs began tracking World Cup-themed phishing activity from the first week of April 2026. What we found was a sustained, accelerating campaign that reached peak intensity in the final days before kickoff and has continued to escalate throughout the tournament itself.

Fig. 1 — Weekly average 'World Cup' subject phish as % of total commodity attacks (Apr 5 - May 10, 2026)

Fig. 2 — Daily "World Cup" subject commodity phish events (Apr 5 - May 14, 2026). April 13 spike at 1.57%
Twelve days into live tournament play, the data confirms a critical trend: rather than peaking on opening day and tapering off, the campaign's activity has steadily escalated.

Fig. 3 — Daily “World Cup” subject phish events (May 14 - Jun 22, 2026). June 7 peak at 1.13%

Fig. 4 — Daily “FIFA” subject phish events (May 14 - Jun 22, 2026). June 1 peak 0.51%, June 10 at 0.44%
Across the full observation window, attackers are heavily favoring display name impersonation over lookalike domain registration — running two-three-times higher than domain-based spoofing. Standard domain reputation filtering provides no protection against this vector.

Fig. 5 — Daily “FIFA” display name phish events (May 14 – Jun 22). Peak: June 10 at 0.74%, June 22 at 0.43%

Fig. 6 — Daily "World Cup" display name phish events (May 14 – Jun 22). Pre-tournament peak June 4 at 0.55%
Key Intelligence: The shift from “World Cup” to “FIFA” as the dominant brand once matches went live is a deliberate tactical switch. FIFA communications are expected by targets during the tournament; the governing body name is the higher-trust signal in a live-match context.
The most technically sophisticated campaign we tracked targets job seekers, not ticket buyers. We are tracking a polished recruiting and survey scam impersonating official FIFA HR and Talent Acquisition teams, weaponizing calendar-booking and fake survey workflows to harvest credentials and steal payment card data.
The attack surface is not incidental. FIFA is actively hiring thousands of staff and volunteers for a 48-team, 16-city tournament. Candidates in application mode expect to share resume data, authenticate and book interviews making them significantly more vulnerable than a generic target.
Targets receive highly customized emails spoofing legitimate FIFA recruitment communications. Senders abuse AWS application services and third-party help-desk platforms to slip past SPF/DKIM filters. Specifically observed infrastructure:
Because these are technically legitimate sending services with valid SPF records, emails arrive at the inbox with a clean authentication pass.

Fig. 7 — “An Opportunity to Connect:” recruiting lure from worldcup2026fifa[.]awsapps[.]com. Note 'View Calendar Availability' CTA - no attachment, sending domain passes SPF.
The email bypasses standard attachment payloads entirely. Instead, it presents a low-friction call to action — “View Calendar Availability” or “Select a time here” — to book a preliminary interview. There is no attachment for scanners to detonate.

Fig. 8 — “FIFA – Invitation to Explore New Roles:” second recruiting variant with calendar CTA. Sent from an unrelated domain with FIFA display name spoofing.
Clicking the calendar link redirects the victim through transactional tracking links (cl[.]s13[.]exct[.]net) onto branded landing pages. Two directly observed:
The redirect chain obscures the final destination from URL scanners that inspect links at delivery time.
To finalize the interview slot, the victim is prompted to authenticate via Google or Microsoft SSO (“Continue with Google”). The moment they attempt to sign in, corporate or personal credentials are harvested in real time.
A parallel track presents a fake survey with Facebook-style dynamic testimonials to build trust. On completion, the kit redirects victims to otakusignalflow[.]com to cover a nominal shipping fee of €2.35 — capturing raw card numbers, CVVs, and expiry dates in real time.

Fig. 9 — Full card-harvest chain: (top-left) FIFA Mystery Box lure; (top-right) otakusignalflow[.]com payment capture page; (bottom) survey pages with fake testimonials.
The recruiting campaign is further supported by a convincing fake FIFA careers portal at fifaworldcup-jobs[.]com, presenting plausible job categories including FIFA World Cup Sponsorship Packages, Free Remote Posting and FIFA World Cup Event Jobs. The domain triggers browser TLS warnings for users with certificate inspection active.

Fig. 10 — fifaworldcup-jobs[.]com fake FIFA careers portal. Left: job listing categories. Right: “Your connection isn't private” browser warning indicating non-standard TLS configuration.
Below the targeted recruiting campaign sits a much higher-volume commodity layer: mass-generated, automated phishing designed to hit as many inboxes as possible, exploiting the genuine scarcity of World Cup tickets and the cultural pull of the tournament.
Most attacks focus on buying, selling and transferring tickets through presale draws or sponsored ticket offers. This method is effective because tickets to high-demand matches are genuinely scarce and carry significant price premiums.
A regional variation has also been noted: U.S.-region traffic is dominated by ticket-transfer fraud. UK-region traffic shows higher volumes of marketing and engagement lures — sponsored watch parties, events and merchandise discounts.
A niche but growing angle surrounds travel, parking and transport at U.S. stadiums, where car-dependent infrastructure creates demand for ride-hailing and parking services. Currently low volume, but expected to scale as the knockout stages attract larger audiences.
Additional lure categories we anticipate but have not yet seen at a significant volume: betting tips and sweepstakes; malicious links to pirate live streaming sites.

Fig. 11 — FIFA ticket transfer phishing email from worldcuptickets.worldcupfifa[.]com. Real FIFA partner logos (Aramco, Adidas, Visa, Coca-Cola, Hyundai) included to increase perceived legitimacy.

Fig. 12 — Watch Party phishing email. Email client flags 'External email', 'First time sender', and 'This email shows strong signs of phishing'.
A German-language variant of the FIFA Mystery Box survey scam was observed, sent from info@grupotrabajopn[.]info and reported June 15, 2026. This confirms the campaign is operating across multiple language markets beyond English-speaking targets.

Fig. 13 — German-language FIFA Mystery Box phishing email (Jun 15, 2026) from grupotrabajopn[.]info. Subject: “[EXT]:[FIFA] Wichtige Nachricht für Sie von FIFA World Cup 2026™.” Confirms multi-language targeting.
A third distinct campaign track was identified in the updated telemetry. Unlike the recruiting and commodity campaigns, these emails contain no malicious links or attachments — making them largely invisible to automated email security tools that scan for technical payload indicators.
Users are enticed with high-value rewards tied to the tournament — ranging from modest incentives (e.g., $50 cash vouchers or free match access) to extravagant VIP luxury ticket packages valued at $8,000+. These lures are designed to trigger excitement, create urgency and lower psychological defenses.
These emails contain no malicious links or attachments. The call to action instructs the victim to reply directly to the sender or manually email a secondary attacker-controlled address to “claim” their prize. There is no technical payload for scanners to inspect.
Once the victim engages, follow-up emails deploy one of two payloads:

Fig. 14 — Advance-fee fraud email posing as “United Nations Compensation Commission,” leveraging FIFA World Cup 2026 context. Sent via canadiansoccerleague[.]org infrastructure. Requests full PII and bank account details.
Defender note: Reply-back campaigns have no payload for scanners to inspect. Detection requires body-level behavioral analysis — specifically, unsolicited prize or reward offers with a reply-only CTA. User awareness training is the primary control against this vector.
All indicators are defanged. Do not resolve or interact with them from production environments. Query using passive DNS, historical WHOIS, Shodan, or sandboxed scanners only. Do not submit raw victim PII to public scanning engines.
Infrastructure reuse note: The pivot domains (manidharipharma[.]online, visionspace[.]cfd, grupotrabajopn[.]info, installtec[.]eng[.]br) are structurally unrelated to FIFA but appear in the same campaign infrastructure. Pivoting through passive DNS may surface additional related infrastructure.
For real-time updates and ongoing threat intelligence, follow the KnowBe4 ThreatLabs on X:@Kb4Threatlabs
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。