Beware of Fake Shops from Threat Actors to Attack Winter Olympics 2026 Fans
Cybercriminals are targeting fans of the Milano Cortina 2026 Winter Olympics through a network of fraudulent online merchandise stores. These fake platforms are designed to steal payment information and personal data from users.
Cybercriminals are targeting fans of the Milano Cortina 2026 Winter Olympics through a network of fraudulent online merchandise stores. These fake platforms are designed to steal payment information and personal data from users.
The scam exploits the demand for official Olympic mascot merchandise, especially Tina and Milo plush toys, which are currently unavailable on the official Olympics store.
Approximately 20 fraudulent domains have been identified in the past week, closely mimicking the official Olympic merchandise store to deceive potential buyers.
These fake shopping sites are not hastily assembled. They replicate the official shop.olympics.com experience, including promotional videos and product layouts, with the only difference being the domain names, such as 2026winterdeals[.]top and olympics-sale[.]shop.
Cybercriminals are targeting fans of the Milano Cortina 2026 Winter Olympics through a network of fraudulent online merchandise stores.
Malwarebytes researchers identified this campaign after observing telemetry data indicating access to these domains from regions including Ireland, the Czech Republic, the United States, Italy, and China. The security team has noted ongoing domain registrations, suggesting a rapid expansion of the operation. Malwarebytes has blocked these domains to protect users.
The fraudulent websites entice users with significant discounts on unavailable items. For instance, while the official Tina plush toy costs €40 and is out of stock, the fake sites advertise it for €20, claiming discounts up to 80%.
The fake Olympic shops have objectives beyond capturing payments without delivering products. They collect payment card details, names, addresses, email addresses, and phone numbers for potential future cyberattacks.
Victims often receive phishing emails aimed at extracting further sensitive information or login credentials. Some scammers distribute malware through fake order confirmations or malicious tracking links.
Security experts recommend purchasing merchandise directly from the official shop.olympics.com website by typing the address into browsers and bookmarking it. Shoppers should avoid clicking links from advertisements, social media posts, or unsolicited emails and be wary of extreme discounts on items that are officially sold out. It's crucial to inspect domain names for suspicious extensions or character substitutions before making purchases.
Based on reporting by Cyber Security News.
