Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

May 22, 2026

New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

May 22, 2026
Facebook X (Twitter) Instagram
Friday, May 22
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Tips and Advice»Scams target soccer fans with fake World Cup tickets, merchandise
Tips and Advice

Scams target soccer fans with fake World Cup tickets, merchandise

Team-CWDBy Team-CWDMay 22, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data

As the FIFA World Cup 2026™ in the United States, Canada, and Mexico draws closer, anticipation is building toward fever pitch. Many soccer fans may still be hunting for tickets, merchandise, travel and hospitality packages – and scammers know exactly how to exploit this demand. In other words, many people are already in the state of mind that scammers count on: interested, impatient and, indeed, maybe a little worried that the tickets or other goods will sell out. Which is ultimately what makes these scams so effective.

ESET researchers in Latin America recently spotted a number of websites that are built for this very moment. Posing as the FIFA association or the official World Cup website, the imposter sites target people looking for tickets and merchandise, then steer them through fake registration and payment flows that steal their money and personal data. The series of steps is often actually the same as on the genuine World Cup website: register, add tickets for a game, jerseys or other merchandise to the cart, and pay.

Some victims may reach these websites through sponsored search results, while others click on ads on social media or links in email messages forwarded by someone who didn’t check the address properly. Whatever the scenario, here’s what you should know about fake FIFA- and World Cup-themed websites – and how to avoid scoring an ‘own goal.’

First sample

One of the fake sites, hosted at https://***fifa26[.]shop, uses a domain that looks close enough to FIFA and the 2026 World Cup to catch a hurried visitor. Indeed, many sites set up in the run-up to major events will rely on a common trick known as typosquatting, which involves on a domain name that closely resembles the legitimate one, but contains small additions or involves other changes in the domain name that the victim often won’t notice.

sitio-falso-fifa-mundial-26-1
Figure 1. Fake site impersonating the official FIFA World Cup 2026™ website

The trickery doesn’t stop there, however. The site also copies the look and feel of FIFA’s official site, including the colors, layout, navigation and ticketing flow, all in order to make the victim feel that the experience is legitimate.

sitio-falso-fifa-mundial-26-2
Figure 2. This website is an imposter

And here, for comparison, is the legitimate website:

sitio-falso-fifa-mundial-26-3
Figure 3. Official FIFA World Cup 2026™ website

But back to the fake website – here’s what happens if you want to “purchase” tickets or merchandise. Much like the official FIFA site, the imposter site also asks you to register. If you expect to create a FIFA ID before buying tickets, a fake registration form may not look strange at first. It also asks for the usual things such as your name, email address, and phone number. Nothing about that feels unusual if you believe you are on FIFA’s official website.

sitio-falso-fifa-mundial-26-4
Figure 4. This site does not sell World Cup tickets

Meanwhile, Figure 5 shows the registration step on the official website.

sitio-falso-fifa-mundial-26-5
Figure 5. User registration on the official FIFA website – noe the URL in the green rectangle

The bogus website also offers what appears to be official merchandise. The point is to keep you inside a familiar shopping routine long enough for the payment page to feel like the next expected step.

sitio-falso-fifa-mundial-26-6
Figure 6. Fake FIFA website
sitio-falso-fifa-mundial-26-7
Figure 7. Bogus store offering team jerseys

It allows you to select any product and add it to the shopping cart:

sitio-falso-fifa-mundial-26-8
Figure 8. Fake shopping site posing as the official FIFA online store

Once you enter your card details, it goes straight to the people behind the fake site – and there’s no jersey coming from FIFA, of course.

sitio-falso-fifa-mundial-26-9
Figure 9. “Purchasing” a soccer jersey on the fake phishing site

The ticket flow works the same way. After registration, the bogus site lets you select supposed World Cup matches, move toward checkout, and reach a payment page. 

sitio-falso-fifa-mundial-26-10
Figure 10. Fake user registration form for World Cup tickets

You can choose the desired match, in any stage of the tournament:

sitio-falso-fifa-mundial-26-11
Figure 11. Bogus payment gateway for World Cup tickets

And then, it leads to the shopping cart. Once entered into the form, your payments details would travel into the hands of the cybercriminal behind the bogus site. 

sitio-falso-fifa-mundial-26-12
Figure 12. Fraudulent page requesting credit card details for a supposed ticket purchase

The obvious loss is money, but the quieter loss is financial and identity data. A full name, email address, phone number and reused password can be misused by attackers beyond any single fraudulent website. If the same password opens your email or social media account, the fake FIFA registration can become the first step in another, and quite possibly even more damaging, attack. 

Four more sites riffing on the same theme

Another fake site, https://****26-fifa[.]com, follows the same pattern. The domain is World Cup-themed, the site uses FIFA’s visuals, and the visitor is pushed toward registration before being offered purported tickets and merchandise.

fake-world-cup-websites
Figure 13. Some other fake sites

The fake World Cup websites in general, including the menu tabs and other visual cues, are designed to look as closely as possible the official one. The top-level domain names matter, too – a .shop or .store domain may make a fake website feel like a retail offshoot, especially when the rest of the URL address contains “fifa” and everything about the site looks polished.

Tactics for staying safe

Crucially, FIFA has made it clear that World Cup tickets can only be bought via three official channels – fifa.com/tickets, fifa.com/hospitality, and special Qatar Airways travel packages (which may actually be sold out by now). It follows then that you’re best off steering clear of various third-party sellers or social media listings.

  • Go to FIFA’s official website directly. Type the address yourself; i.e., start from FIFA.com or FIFA’s ticketing portal, not from an ad, a social media post or a link someone has sent to you.
  • Look closely at the domain name before entering any information. Extra characters, words, odd endings and near-matches could be the only visible clue that the site is not what it claims to be.
  • Be careful with offers built around pressure: “limited tickets,” “VIP access,” “discounts,” “last chance,” or anything that rushes you into action and makes checking feel like a delay you can’t afford.
  • Avoid reusing passwords. If a fake registration page steals a password that you also use for your email, social media or banking account, the problem could follow you way beyond the fake site.
  • And don’t let a checkout flow reassure you. A working cart and a payment form don’t prove that the seller is legitimate.
  • Protect all your accounts with strong, unique passwords and two-factor authentication, as well as use security software on all your devices.

The countdown to the World Cup gives criminals a ready-made audience: countless people hunting for tickets, merchandise and various last-minute opportunities. The fake FIFA sites show how that demand is being turned into a phishing flow, one familiar click at a time. Stay safe!



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWindows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
Team-CWD
  • Website

Related Posts

Tips and Advice

The quest for greater tech independence

May 19, 2026
Tips and Advice

Why geopolitical turmoil is a gift for scammers, and how to stay safe

May 15, 2026
Tips and Advice

How to mitigate the security and privacy risks of smart glasses

May 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Find your weak spots before attackers do

November 21, 2025

Why you should never pay to get paid

September 15, 2025

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.