Thousands of Fake Websites Target World Cup Fans with Scams
Trend Micro research reveals over 35,000 malicious websites impersonating official FIFA World Cup 2026 entities, attracting millions of visits and employing sophisticated tactics to steal financial data.

Cybercriminals have launched a massive wave of scams targeting fans of the 2026 FIFA World Cup, creating over 35,000 fake websites designed to defraud unsuspecting users. Between January and June 2026, Trend Micro's TrendAI platform identified these malicious sites, which collectively garnered approximately 1.48 million visits, with a significant portion originating from Japan. The scams exploit the global excitement surrounding the tournament, which was co-hosted by the United States, Canada, and Mexico from June 11 to July 19, 2026.
The fraudulent online activities fall into three primary categories: counterfeit merchandise shops, deceptive ticket sales pages, and fake live-streaming sites. These operations aim to capitalize on fans' desire for official gear, match access, and viewing opportunities. It is crucial to note that these scams are entirely separate from FIFA and its official partners, who are not involved in these malicious activities.
Fake merchandise sites, numbering 6,251, were found to be selling counterfeit goods. Attackers employed techniques like SEO poisoning to ensure these sites appeared prominently in search engine results. While many of these sites were established before the tournament, their offerings closely mimicked legitimate Japanese online stores, aiming to trick consumers into purchasing low-quality or non-existent items.
More dangerous are the cloned ticket and hospitality sites. These pages meticulously replicate official FIFA hospitality websites, even embedding images and videos from legitimate sources and linking to official social media and policy documents to enhance credibility. The primary goal of these sites is to harvest user credentials, including email addresses and passwords, through fake login pages.
The most alarming aspect of these cloned ticket sites is their ability to bypass multi-factor authentication. When users attempt to 'purchase' tickets or packages, they are led through a checkout process that captures credit card details. Even if a one-time password (OTP) is sent for verification, the fake site prompts the user to enter it directly, allowing attackers to immediately use the stolen credentials for fraudulent transactions elsewhere.
Fake streaming sites also played a role in the scam campaign, promising live broadcasts of matches that never materialize. These sites often serve as a gateway for further malware distribution or credential harvesting, preying on fans' desire to watch games they might otherwise miss.
The FBI's Internet Crime Complaint Center (IC3) issued a public service announcement in May 2026, warning of these tournament-related scams. The surge in traffic to malicious sites in June directly coincided with the tournament's kickoff, indicating the attackers' strategy to maximize engagement during the event's peak.
Trend Micro advises users to exercise extreme caution. Navigating directly to official websites, being suspicious of offers that seem too good to be true, and never entering OTPs on pages accessed through search results or advertisements are critical steps in avoiding these sophisticated World Cup-themed scams.