Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Phishing and Spoofed Sites Remain Primary Entry Points For Olympics
News

Phishing and Spoofed Sites Remain Primary Entry Points For Olympics

Team-CWDBy Team-CWDJanuary 21, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new assessment of cyber risks facing the Milano-Cortina 2026 Winter Games has highlighted phishing and spoofed websites as the most common initial access points for attackers targeting global sporting events. 

The findings have been detailed in Palo Alto Networks’ Cyber Threats to Milan-Cortina 2026 report, which examined how criminal groups, state-backed actors and hacktivists are likely to exploit the Games’ vast digital footprint.

The research draws on recent Olympic history. During the Pyeongchang 2018 games, attackers disrupted WiFi and digital infrastructure. Ahead of Tokyo 2021, Russian-linked groups attempted to interfere with pre-Games operations. At Paris 2024, analysts observed spikes in DDoS activity, Olympics-themed phishing and online scams. With more than 3 billion viewers expected for Milano-Cortina, the incentives remain high.

The Palo Alto report emphasized how attackers blend speed with deception. Phishing campaigns, often tied to business email compromise (BEC), continue to dominate the early stages of intrusions. Researchers noted that 76% of observed phishing cases relied on BEC, exploiting trust between staff, partners and suppliers across the Olympic ecosystem.

“The biggest risks to large events like the Olympics don’t come from new exploits,” Randolph Barr, CISO at Cequence Security, said. “Instead, they originate from people misusing legitimate apps, identities and corporate processes.”

Common Tactics Observed Around the Games

The Games attract a broad mix of threat actors. Financially motivated ransomware gangs see ticketing platforms, event websites and payment systems as leverage points. Nation-state groups focus on espionage, using the proximity of diplomats and officials to quietly collect intelligence over long periods. Hacktivist groups, meanwhile, seek disruption and publicity.

Examples cited include Dark Scorpius, which has compromised more than 500 victims since 2022 by impersonating IT staff and gaining remote access in as little as 14 hours, and Fighting Ursa, a Russia-linked group known for phishing via spoofed sites and weaponised documents.

Read more on phishing and social engineering: LinkedIn Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs 

Researchers outline several techniques likely to recur around Milano-Cortina:

  • Phishing and spoofed websites used to harvest credentials

  • Exploitation of software and API vulnerabilities in complex event systems

  • Use of previously compromised credentials bought on the dark web

  • DDoS attacks aimed at ticketing, turnstiles and event websites

For consumers and employees alike, basic caution still applies. “If it sounds too good to be true, it probably is,” Trey Ford, chief strategy and trust officer at Bugcrowd, said. “Buying from reputable sources […] is the only way to avoid credit card theft and counterfeit products.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks
Next Article 2025’s most common passwords were as predictable as ever
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Fixing trivial passwords is as easy as 123456

May 7, 2026

Here’s how to avoid a ‘second strike’

April 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.