Overview
- The FBI has publicly warned that cybercriminals are registering and operating hundreds of fake FIFA‑looking domains to steal personal and payment data and sell counterfeit World Cup tickets and hospitality packages.
- Meta said it is rolling out in‑app ticket warnings, new AI detection and intelligence sharing with partners such as Visa after a joint disruption of a scam network that routed users from Facebook pages to fraudulent gambling sites.
- Security researchers including Unit 42 and Group‑IB have tracked thousands of suspicious domains and highlighted multiple attack types — fake ticket sites, phishing, QR‑code fraud, malicious streaming apps, accommodation scams and infostealer malware families.
- Authorities and platforms advise concrete steps for fans: type fifa.com or use a saved bookmark, avoid sponsored search links, enable multi‑factor authentication, verify sellers through FIFA’s official channels and report fraud to the IC3 for takedown and investigation.
- With 16 host cities across the U.S., Canada and Mexico and millions of travelers expected, experts warn many dormant domains and cross‑platform campaigns could be activated in the run‑up to kickoff, raising risks for travelers and remote viewers.