World Cup Phishing Campaign Surges: 203 Unique IP Addresses Target Fans
Key Takeaways A sophisticated phishing campaign targeting the 2026 FIFA World Cup has dramatically expanded, now encompassing 222 fraudulent domains across 203 unique IP addresses. Threat actors are...
Key Takeaways
- A sophisticated phishing campaign targeting the 2026 FIFA World Cup has dramatically expanded, now encompassing 222 fraudulent domains across 203 unique IP addresses.
- Threat actors are employing convincing replicas of the official FIFA website to steal payment information and user credentials from unsuspecting football fans.
- The operation is not a single, coordinated attack but a distributed fraud ecosystem managed by at least four distinct clusters of operators.
- A significant portion of the malicious infrastructure is hosted behind Cloudflare, with GNAME.COM and GoDaddy serving as the primary registrars for the fraudulent domains.
- The campaign continues to grow rapidly, with 52 new domains registered in the first 17 days of April 2026 alone, indicating an accelerating threat ahead of the tournament.
World Cup Phishing Campaign Scales Rapidly Ahead of 2026 Tournament
A widespread phishing operation aimed at defrauding fans of the 2026 FIFA World Cup has surged in scale, nearly tripling its initial footprint. Security researchers initially identified 79 malicious domains; this network has now ballooned to at least 222 domains, hosted across 203 distinct IP addresses. This substantial increase in infrastructure highlights the growing threat, as detailed in a recent report by Flare.
Table Of Content
The attackers’ methodology is designed to be highly deceptive. They meticulously craft counterfeit versions of the official FIFA website, featuring fake ticketing portals, imitation merchandise stores, and fraudulent login pages. These deceptive pages are engineered to accept any credentials entered, enabling threat actors to harvest sensitive account details and steal payments from eager football enthusiasts.
Deep Dive into the Expanding Infrastructure
Researchers at Flare uncovered the full scope of this operation by leveraging passive DNS records, certificate transparency logs, and WHOIS data enrichment. Their investigation revealed that the campaign is not a singular, centrally managed attack but rather a complex, distributed fraud ecosystem comprising at least four distinct operator clusters, all focused on exploiting the upcoming tournament.
The updated analysis shows 222 domains, with 206 currently active, resolving to 203 unique IP addresses. This represents a 2.8-fold increase in domain count and a more than 14-fold expansion in hosting infrastructure compared to earlier assessments. A notable 80.6 percent of these malicious IP addresses are concealed behind Cloudflare, which threat actors are utilizing as a reverse proxy to obscure their true server locations. Five IP addresses were found to host multiple domains, with one IP alone linked to eight separate fraudulent sites. Independently, Cloudflare has identified three domains within the dataset as suspected phishing pages, corroborating the malicious nature of the activity.
The landscape of domain registrars has also evolved. GNAME.COM remains the primary registrar, managing approximately 94 domains, which accounts for about 42 percent of the identified infrastructure. GoDaddy follows with 42 domains, meaning these two registrars collectively control roughly 61 percent of the entire network. Researchers recommend that brand protection teams prioritize bulk abuse reporting to GNAME.COM and GoDaddy to maximize the impact of takedown efforts.
Four Distinct Operator Clusters Behind the Fraud
A key finding from Flare’s research is the identification of at least four separate operator clusters. These groups exhibit varying registration patterns, hosting preferences, and digital fingerprints, suggesting independent actors rather than a single coordinated entity. All four clusters, however, deploy identical page templates and target the same victim pool, indicating a shared scam kit or similar operational tactics.
- Cluster A: This is the most prominent cluster, managing approximately 86 domains that closely mimic the official fifa.com address.
- Cluster B: More stealthy, this cluster operates 14 .shop domains with generic names that initially show no direct connection to FIFA but redirect to the same fraudulent landing pages.
- Cluster C: A smaller group, this cluster consists of three .cn domains registered via a single Gmail address, suggesting a China-based independent actor.
- Cluster D: This cluster employs a fabricated registrant identity, “888 World Cup Management Co Ltd,” openly referencing the tournament in its cover.
Given the distributed nature of this threat, detection strategies must evolve beyond individual domain analysis to a campaign-level approach. Security teams are advised to move beyond simple naming pattern analysis and integrate TLS certificate reuse and page template fingerprinting into their detection rules. Furthermore, any newly registered domain matching known WHOIS indicators should be considered an active part of this ongoing campaign.
What You Should Do
- Verify URLs: Always double-check the URL of any website offering World Cup tickets or merchandise. Look for “https://” and ensure the domain name is legitimate (e.g., fifa.com), not a variation or misspelling.
- Avoid Suspicious Links: Do not click on links in unsolicited emails, text messages, or social media posts related to the World Cup, even if they appear to be from official sources. Navigate directly to the official FIFA website.
- Use Strong, Unique Passwords: Employ strong, unique passwords for all online accounts, especially those involving financial transactions. Consider using a password manager.
- Enable Multi-Factor Authentication (MFA): Activate MFA on any accounts that support it, particularly for email, banking, and ticketing platforms. This adds an extra layer of security.
- Monitor Financial Statements: Regularly review bank and credit card statements for any unauthorized transactions. Report suspicious activity immediately to your financial institution.
- Report Phishing Attempts: If you encounter a suspicious website or email, report it to the relevant authorities and the legitimate organization being impersonated.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| IP Address | 38.246.249.74 | Top hosting IP, tied to 8 campaign domains |
| IP Address | 154.39.81.213 | Hosting IP tied to 6 campaign domains |
| IP Address | 148.178.16.48 | Hosting IP tied to 5 campaign domains |
| IP Address | 154.86.0.33 | Shared campaign hosting IP |
| IP Address | 104.225.235.49 | Shared campaign hosting IP |
| [email protected] | Registrant email linked to 14 Cluster B .shop domains | |
| [email protected] | Registrant email linked to 3 Cluster C .cn domains | |
| Registrant Organization | 888 shi jie bei guan li you xian gong si | Cluster D fake registrant identity (888 World Cup Management Co Ltd) |
| Registrant Contact | Bill John / Newark | Cluster B placeholder identity tied to 14 .shop domains |
| TLS Certificate Hash | 1b02595c66a13a4a5a523a76de25803bdb950623 | Shared across 3 campaign domains |
| TLS Certificate Hash | fc1db8def38bb08010bb8f8ac14d5e498ff8ff43 | Shared across 2 campaign domains |
| TLS Certificate Hash | 3b8bb7631b39f455d31544b55ba97b49ab1888c1 | Shared across 2 campaign domains |
| TLS Certificate Hash | fb0498ab592232747a4d90aa150ee4e0506869ca | Shared across 2 campaign domains |
| Domain | fifa-com.store | Cloudflare-flagged suspected phishing domain |
| Domain | fifa-com.site | Cloudflare-flagged suspected phishing domain |
| Domain | fifa-com.shop | Cloudflare-flagged suspected phishing domain |
| Domain | dustdigitalsw.shop | Cluster B domain originally registered July 2015, repurposed for World Cup fraud |
| Domain | https-fifa.cn | Cluster C .cn domain, registered March 28, 2026 |
| Domain | ww-fifaweb.cn | Cluster C .cn domain, registered March 28, 2026 |
| Domain | fifawebsite.cn | Cluster C .cn domain, registered March 28, 2026 |
| Domain | www-fifaworldcup.one | Cluster D domain, registrant org: 888 World Cup Management Co Ltd |
| Domain | www-fifaworldcup.vip | Cluster D domain, registrant org: 888 World Cup Management Co Ltd |
| Domain | fifa-com.one | Cluster D domain, registrant org: 888 World Cup Management Co Ltd |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.