Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Carnival Cruise Data Breach Exposes Millions of Customer
May 28, 2026
Hackers Use GHOSTYNETWORKS & OMEGATE OMEGATECH Malware
May 28, 2026
Hackers Bypass DNS Filters Using Shared CDN Edge Abuse Protective
May 28, 2026
Home/CyberSecurity News/Threat Actors Spoof FIFA Sites to Steal Personal Data
CyberSecurity News

Threat Actors Spoof FIFA Sites to Steal Personal Data

Ahead of the 2026 FIFA World Cup, threat actors are actively spoofing official FIFA websites. They are targeting unsuspecting users to steal sensitive personal data, including names, home addresses,...

Marcus Rodriguez
Marcus Rodriguez
May 28, 2026 3 Min Read
3 0

Ahead of the 2026 FIFA World Cup, threat actors are actively spoofing official FIFA websites. They are targeting unsuspecting users to steal sensitive personal data, including names, home addresses, and phone numbers.

According to the FBI, attackers are creating highly convincing replica websites that mimic the legitimate FIFA domain, www.fifa.com, using techniques such as typo-squatting and domain impersonation.

Fake FIFA Sites Steals

The warning, issued by the Federal Bureau of Investigation (FBI) under Alert I-052726-PSA on May 27, 2026, highlights a growing wave of phishing infrastructure targeting the global excitement surrounding the tournament.

These malicious domains often include subtle misspellings or alternative top-level domains, allowing them to evade casual detection.

Examples identified include FIFA. [cab], FIFA. []pink, FIFA [.]pub, fifa[.]ceo, and more deceptive variants such as wvvw-fifa[.]com and fifa-com[.]com.

These spoofed platforms are engineered to appear legitimate, often replicating official branding, ticket portals, and career pages.

In many cases, users are lured into interacting with fake ticket sales, hospitality packages, or job opportunities linked to the World Cup.

Once users engage, they are prompted to submit personally identifiable information (PII), including full names, residential addresses, email accounts, and phone numbers. In more advanced scenarios, financial data may also be collected.

The FBI notes that threat actors leverage this stolen information for identity theft, financial fraud, and account takeover attacks.

Victims may unknowingly enable attackers to create fraudulent accounts in their name or conduct unauthorized transactions.

Additionally, some campaigns may involve layered scams in which victims are redirected via malicious advertisements or search engine “sponsored” results that prioritize attacker-controlled domains.

A notable tactic observed in this campaign is the abuse of subdomain impersonation and employment-related lures.

Domains such as jobs-fifa[.]com, fifa-careerhub[.]com, and fifaworldcup-careers[.]com are specifically crafted to target job seekers hoping to work with FIFA during the World Cup.

Similarly, fake ticketing platforms like fifa-ticket[.]live and worldcup26ticket[.]com attempted to exploit high-demand ticket sales. The infrastructure supporting these attacks is expected to expand significantly as the tournament approaches.

The FBI warns that new malicious domains will continue to emerge, increasing the attack surface and making detection more challenging for average users.

From a technical perspective, this campaign underscores the continued effectiveness of social engineering combined with domain-based deception.

Attackers rely heavily on user trust, visual similarity, and urgency-driven interactions. The use of alternative top-level domains such as .xyz, .online, and .shop further complicates traditional filtering mechanisms, especially when paired with HTTPS certificates that give a false sense of legitimacy.

Security experts emphasize that direct navigation to official domains remains one of the most effective defenses.

Users are advised to enter URLs manually rather than relying on search engines, as malicious actors frequently manipulate paid search results.

Bookmarking verified websites and avoiding unsolicited links are also critical preventive measures. The FBI encourages victims or individuals who encounter suspicious domains to report incidents to the Internet Crime Complaint Center (IC3).

Reports should include details such as the fraudulent domain, interaction history, and any financial transactions associated with the incident.

As global events like the FIFA World Cup attract massive online engagement, they also present lucrative opportunities for cybercriminals.

This campaign highlights the importance of vigilance, domain awareness, and proactive cybersecurity practices in mitigating phishing and identity theft risks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Top 10 SAST Tools for Security Teams in Best Static

Next Post

Top 10 Best MAST Tools for Mobile App Security Application Testing

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
PureLogs Variant Evades Detection via MsBuild.exe Process
May 28, 2026
Top 10 Best MAST Tools for Mobile App Security Application Testing
May 28, 2026
Threat Actors Spoof FIFA Sites to Steal Personal Data
May 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us