Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenClaw AI Agent Exploits Gym API to Steal Workout Slot
August 10, 2026
Microsoft Teams to Gain New Security Detection Reporting Feature
August 9, 2026
Critical Metabase Vulnerability Exploited to Gain Admin Access
August 9, 2026
Home/Threats/World Cup Phishing Campaign Surges: 203 Unique IP Addresses Target Fans
Threats

World Cup Phishing Campaign Surges: 203 Unique IP Addresses Target Fans

Key Takeaways A sophisticated phishing campaign targeting the 2026 FIFA World Cup has dramatically expanded, now encompassing 222 fraudulent domains across 203 unique IP addresses. Threat actors are...

Emy Elsamnoudy
Emy Elsamnoudy
May 22, 2026 5 Min Read
77 0

Key Takeaways

  • A sophisticated phishing campaign targeting the 2026 FIFA World Cup has dramatically expanded, now encompassing 222 fraudulent domains across 203 unique IP addresses.
  • Threat actors are employing convincing replicas of the official FIFA website to steal payment information and user credentials from unsuspecting football fans.
  • The operation is not a single, coordinated attack but a distributed fraud ecosystem managed by at least four distinct clusters of operators.
  • A significant portion of the malicious infrastructure is hosted behind Cloudflare, with GNAME.COM and GoDaddy serving as the primary registrars for the fraudulent domains.
  • The campaign continues to grow rapidly, with 52 new domains registered in the first 17 days of April 2026 alone, indicating an accelerating threat ahead of the tournament.

World Cup Phishing Campaign Scales Rapidly Ahead of 2026 Tournament

A widespread phishing operation aimed at defrauding fans of the 2026 FIFA World Cup has surged in scale, nearly tripling its initial footprint. Security researchers initially identified 79 malicious domains; this network has now ballooned to at least 222 domains, hosted across 203 distinct IP addresses. This substantial increase in infrastructure highlights the growing threat, as detailed in a recent report by Flare.

Table Of Content

  • Key Takeaways
  • World Cup Phishing Campaign Scales Rapidly Ahead of 2026 Tournament
  • Deep Dive into the Expanding Infrastructure
  • Four Distinct Operator Clusters Behind the Fraud
  • What You Should Do
  • Indicators of Compromise (IoCs)

The attackers’ methodology is designed to be highly deceptive. They meticulously craft counterfeit versions of the official FIFA website, featuring fake ticketing portals, imitation merchandise stores, and fraudulent login pages. These deceptive pages are engineered to accept any credentials entered, enabling threat actors to harvest sensitive account details and steal payments from eager football enthusiasts.

Deep Dive into the Expanding Infrastructure

Researchers at Flare uncovered the full scope of this operation by leveraging passive DNS records, certificate transparency logs, and WHOIS data enrichment. Their investigation revealed that the campaign is not a singular, centrally managed attack but rather a complex, distributed fraud ecosystem comprising at least four distinct operator clusters, all focused on exploiting the upcoming tournament.

The updated analysis shows 222 domains, with 206 currently active, resolving to 203 unique IP addresses. This represents a 2.8-fold increase in domain count and a more than 14-fold expansion in hosting infrastructure compared to earlier assessments. A notable 80.6 percent of these malicious IP addresses are concealed behind Cloudflare, which threat actors are utilizing as a reverse proxy to obscure their true server locations. Five IP addresses were found to host multiple domains, with one IP alone linked to eight separate fraudulent sites. Independently, Cloudflare has identified three domains within the dataset as suspected phishing pages, corroborating the malicious nature of the activity.

The landscape of domain registrars has also evolved. GNAME.COM remains the primary registrar, managing approximately 94 domains, which accounts for about 42 percent of the identified infrastructure. GoDaddy follows with 42 domains, meaning these two registrars collectively control roughly 61 percent of the entire network. Researchers recommend that brand protection teams prioritize bulk abuse reporting to GNAME.COM and GoDaddy to maximize the impact of takedown efforts.

Four Distinct Operator Clusters Behind the Fraud

A key finding from Flare’s research is the identification of at least four separate operator clusters. These groups exhibit varying registration patterns, hosting preferences, and digital fingerprints, suggesting independent actors rather than a single coordinated entity. All four clusters, however, deploy identical page templates and target the same victim pool, indicating a shared scam kit or similar operational tactics.

  • Cluster A: This is the most prominent cluster, managing approximately 86 domains that closely mimic the official fifa.com address.
  • Cluster B: More stealthy, this cluster operates 14 .shop domains with generic names that initially show no direct connection to FIFA but redirect to the same fraudulent landing pages.
  • Cluster C: A smaller group, this cluster consists of three .cn domains registered via a single Gmail address, suggesting a China-based independent actor.
  • Cluster D: This cluster employs a fabricated registrant identity, “888 World Cup Management Co Ltd,” openly referencing the tournament in its cover.

Given the distributed nature of this threat, detection strategies must evolve beyond individual domain analysis to a campaign-level approach. Security teams are advised to move beyond simple naming pattern analysis and integrate TLS certificate reuse and page template fingerprinting into their detection rules. Furthermore, any newly registered domain matching known WHOIS indicators should be considered an active part of this ongoing campaign.

What You Should Do

  • Verify URLs: Always double-check the URL of any website offering World Cup tickets or merchandise. Look for “https://” and ensure the domain name is legitimate (e.g., fifa.com), not a variation or misspelling.
  • Avoid Suspicious Links: Do not click on links in unsolicited emails, text messages, or social media posts related to the World Cup, even if they appear to be from official sources. Navigate directly to the official FIFA website.
  • Use Strong, Unique Passwords: Employ strong, unique passwords for all online accounts, especially those involving financial transactions. Consider using a password manager.
  • Enable Multi-Factor Authentication (MFA): Activate MFA on any accounts that support it, particularly for email, banking, and ticketing platforms. This adds an extra layer of security.
  • Monitor Financial Statements: Regularly review bank and credit card statements for any unauthorized transactions. Report suspicious activity immediately to your financial institution.
  • Report Phishing Attempts: If you encounter a suspicious website or email, report it to the relevant authorities and the legitimate organization being impersonated.

Indicators of Compromise (IoCs):

Type Indicator Description
IP Address 38.246.249.74 Top hosting IP, tied to 8 campaign domains
IP Address 154.39.81.213 Hosting IP tied to 6 campaign domains
IP Address 148.178.16.48 Hosting IP tied to 5 campaign domains
IP Address 154.86.0.33 Shared campaign hosting IP
IP Address 104.225.235.49 Shared campaign hosting IP
Email [email protected] Registrant email linked to 14 Cluster B .shop domains
Email [email protected] Registrant email linked to 3 Cluster C .cn domains
Registrant Organization 888 shi jie bei guan li you xian gong si Cluster D fake registrant identity (888 World Cup Management Co Ltd)
Registrant Contact Bill John / Newark Cluster B placeholder identity tied to 14 .shop domains
TLS Certificate Hash 1b02595c66a13a4a5a523a76de25803bdb950623 Shared across 3 campaign domains
TLS Certificate Hash fc1db8def38bb08010bb8f8ac14d5e498ff8ff43 Shared across 2 campaign domains
TLS Certificate Hash 3b8bb7631b39f455d31544b55ba97b49ab1888c1 Shared across 2 campaign domains
TLS Certificate Hash fb0498ab592232747a4d90aa150ee4e0506869ca Shared across 2 campaign domains
Domain fifa-com.store Cloudflare-flagged suspected phishing domain
Domain fifa-com.site Cloudflare-flagged suspected phishing domain
Domain fifa-com.shop Cloudflare-flagged suspected phishing domain
Domain dustdigitalsw.shop Cluster B domain originally registered July 2015, repurposed for World Cup fraud
Domain https-fifa.cn Cluster C .cn domain, registered March 28, 2026
Domain ww-fifaweb.cn Cluster C .cn domain, registered March 28, 2026
Domain fifawebsite.cn Cluster C .cn domain, registered March 28, 2026
Domain www-fifaworldcup.one Cluster D domain, registrant org: 888 World Cup Management Co Ltd
Domain www-fifaworldcup.vip Cluster D domain, registrant org: 888 World Cup Management Co Ltd
Domain fifa-com.one Cluster D domain, registrant org: 888 World Cup Management Co Ltd

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Hackers Exploit Middle East Telecoms for C2 Operations

Next Post

Anthropic Claude Mythos Preview Finds 10,000 Zero-Days in Project Glasswing

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us