World Cup phishing campaign grows to 222 fake domains across 203 IP addresses
A phishing campaign targeting 2026 FIFA World Cup fans has grown far beyond its first known footprint, with researchers now tracking at least 222 fraudulent domains across 203 unique IP addresses.
The expanded Flare investigation found that the operation is almost three times larger than the first public dataset suggested. The fake sites imitate FIFA pages, ticketing flows, merchandise stores, and login screens to steal payments and account credentials from fans.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The campaign matters because demand for World Cup tickets creates ideal conditions for fraud. Attackers can exploit urgency, scarcity, high resale prices, and confusion around ticket availability to push users toward fake websites before they check the official source.
The phishing infrastructure is still expanding
The original research identified 79 typosquatting and lookalike domains hosted across 14 IP addresses. The newer dataset adds another 143 domains, bringing the total to 222 domains, with 206 still active when the research was published.
The hosting footprint also grew sharply. Researchers found 203 unique IP addresses, and 80.6% of them sat behind Cloudflare. Flare said the attackers are likely using Cloudflare as a reverse proxy to hide the real origin servers behind the phishing sites.
The earlier Flare report showed how the first wave of fake sites copied FIFA website structures, pushed users through fake ticket and store pages, and accepted login details on a fake FIFA ID screen.
| Finding | Earlier dataset | Expanded dataset |
|---|---|---|
| Fraudulent domains | 79 | 222 |
| Unique IP addresses | 14 | 203 |
| Currently active domains | Not the full expanded set | 206 |
| Cloudflare-proxied IPs | Not the main focus | 80.6% |
| Known operator clusters | Initially looked more centralized | At least four clusters |
Fake FIFA pages target tickets, merchandise, and accounts
The phishing pages are designed to look convincing. Some domains mimic FIFA naming patterns directly, while others use broader World Cup wording that can still look trustworthy to fans searching for tickets or merchandise.
Many pages copy the look and flow of legitimate FIFA services. Some include fake ticketing screens, fake store pages, and login pages that accept any credentials. This suggests the sites can support both direct payment fraud and credential harvesting.
Fans should use the official FIFA ticketing page instead of clicking links from ads, social media posts, messaging apps, or unfamiliar search results. Fraudulent domains often rely on small spelling changes, odd top-level domains, and rushed checkout flows.
Four operator clusters appear to be involved
The expanded dataset does not point to one single operator. Flare found at least four distinct clusters with different registration patterns, hosting choices, and WHOIS fingerprints.
Cluster A is the largest and includes roughly 86 domains that directly imitate fifa.com. Cluster B uses 14 .shop domains with generic names that do not obviously mention FIFA, but still serve the same fraudulent landing page.
Cluster C includes three .cn domains registered through one Gmail address. Cluster D uses a fake registrant identity translated as “888 World Cup Management Co Ltd,” which openly references the tournament in the cover identity.
| Cluster | Known pattern | Why it matters |
|---|---|---|
| Cluster A | About 86 domains directly mimic fifa.com | Most visible typosquatting group |
| Cluster B | 14 generic .shop domains | Harder to detect through FIFA naming alone |
| Cluster C | Three .cn domains tied to one email pattern | Suggests a smaller independent operator |
| Cluster D | Fake “888 World Cup Management” registrant identity | Uses tournament-themed cover details |
Registrars and hosting patterns reveal the scale
GNAME.COM remained the dominant registrar in the expanded dataset, accounting for about 94 domains. GoDaddy followed with 42 domains. Together, the two registrars controlled about 61% of the known infrastructure.
That concentration gives brand protection teams a practical route for action. Bulk abuse reports to the most-used registrars could remove a large share of the active domain network faster than one-off domain complaints.
Flare’s expanded research also found that 52 additional domains were registered between April 1 and April 17, 2026. That shows the campaign is growing as the tournament approaches rather than winding down.
Attackers are preparing before fans start buying
World Cup fraud infrastructure does not always appear at the last minute. Some domains sit dormant before attackers activate them, which helps them look older and less suspicious when fans start searching for tickets.
Netcraft warned that fake World Cup domains had already been registered months before kickoff, with some built to gain search credibility, SSL certificates, and traffic signals before phishing pages went live.
This pattern creates a problem for traditional brand monitoring. If a company only reacts after a fake site displays copied logos or payment pages, the attacker may already have built the domain reputation needed to reach victims.
Why fans are at risk
World Cup tickets create a perfect phishing theme because many fans expect limited availability, queues, lotteries, resale offers, and urgent payment windows. Scammers use that pressure to make suspicious checkout flows feel normal.
Fake websites may also imitate official branding closely enough to fool users on mobile screens. A small domain change can disappear visually, especially when the page uses real images, copied layouts, and tournament language.
- Fake ticket pages may offer seats that do not exist.
- Copycat stores may collect payment for merchandise that never ships.
- Fake FIFA ID pages may harvest email addresses and passwords.
- Payment pages may push users toward crypto or payment apps.
- Lookalike domains may appear in search results, ads, or social posts.
- Scam pages may use HTTPS, which does not prove the site is official.
How to spot a fake World Cup ticket site
Fans should check the domain before entering login or payment details. Criminals often register domains that replace letters, add hyphens, use extra words, or attach FIFA-related terms to unfamiliar extensions.
The safest route is to type the known FIFA domain directly into the browser or use the official FIFA app. A website that promises guaranteed tickets, asks for crypto payments, skips seat selection, or accepts obviously fake credentials should be treated as suspicious.
The official FIFA ticket page remains the central place for ticket and hospitality information, while unofficial links should receive extra scrutiny before users enter personal or financial data.
What security teams should do
Security teams should not treat this as a domain-by-domain problem. The campaign uses shared templates, registrar patterns, certificate reuse, WHOIS details, infrastructure overlap, and common page fingerprints.
That means defenders should track the whole campaign, not only obvious fifa.com lookalikes. Generic .shop domains and older repurposed domains may serve the same fraud pages without using obvious FIFA wording.
- Monitor new domains using FIFA, World Cup, ticket, merch, resale, and host city terms.
- Track TLS certificate reuse across suspicious websites.
- Cluster domains by page templates and checkout flows.
- Watch registrar patterns and WHOIS fields linked to known clusters.
- Prioritize abuse reports to registrars with the largest domain counts.
- Warn customers not to trust links from ads, social posts, or messaging apps.
- Look for generic domains that serve known phishing templates.
Domain aging makes the threat harder to stop
Attackers can register domains long before they need them, then activate the pages when search demand spikes. This gives fraud teams less time to react once the site starts collecting payments.
Netcraft’s analysis described this as a domain protection gap because suspicious domains can look harmless while dormant. By the time they host copied ticket pages, they may already have age, certificates, and search visibility.
The same lesson applies beyond the World Cup. Any major event with tickets, travel, merchandise, hospitality, or urgent booking windows can attract early domain registration and later phishing activation.
Why this campaign matters
The 2026 FIFA World Cup gives scammers a global audience and a clear financial target. Fans want tickets, teams want merchandise sales, and brands want visibility. Attackers can abuse all three.
The campaign’s growth from 79 domains to 222 domains shows how fast event-based fraud can scale. The use of at least four operator clusters also suggests that multiple groups may be sharing or adapting the same scam kit.
The earlier Flare findings showed the scam flow from fake FIFA pages to fake checkout behavior. The newer Flare research shows that the operation is broader, more distributed, and still adding infrastructure.
The practical advice is simple: fans should start from official FIFA channels, and defenders should track campaign patterns instead of waiting for individual phishing domains to become active.
FAQ
Researchers found at least 222 fraudulent domains across 203 unique IP addresses, with 206 domains active at the time of the expanded investigation.
The websites are designed to steal payments, FIFA account credentials, personal details, and other information from fans looking for tickets or merchandise.
Some domains directly mimic fifa.com, while others use generic .shop names or older domains that do not obviously reference FIFA. Attackers also reuse page templates, certificates, and hosting patterns across clusters.
Fans should start from FIFA’s official website or app, check the domain carefully, avoid links from ads or social media messages, reject crypto-only payment flows, and avoid sites that promise unrealistic ticket availability.
Security teams should monitor lookalike domains, certificate reuse, page templates, WHOIS details, registrar patterns, Cloudflare-proxied infrastructure, and generic domains that serve known scam pages.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages